Article Details
Scrape Timestamp (UTC): 2023-12-15 14:54:39.304
Original Article Text
Click to Toggle View
Delta Dental says data breach exposed info of 7 million people. Delta Dental of California is warning almost seven million patients that they suffered a data breach after personal data was exposed in a MOVEit Transfer software breach. Delta Dental is a dental insurance provider that covers 85 million people across 50 states, but this data breach notice concerns the California division of the company. According to a Delta Dental data breach notification, the company suffered unauthorized access by threat actors through the MOVEit file transfer software application. The software was vulnerable to a zero-day SQL injection flaw leading to remote code execution, tracked as CVE-2023-34362, which the Clop ransomware gang leveraged to breach thousands of organizations worldwide. Delta Dental learned about the compromise on June 1, 2023, and five days later, following an internal investigation, it confirmed that unauthorized actors had accessed and stolen data from its systems between May 27 and May 30, 2023. The second, more lengthy investigation to determine the exact impact of the security incident was completed on November 27, 2023. Based on this, the data breach has so far impacted 6,928,932 customers of Delta Dental, who had their names, financial account numbers, and credit/debit card numbers, including security codes, exposed. Delta Dental provides 24 months of free credit monitoring and identity theft protection services to impacted patients to mitigate the risk of their exposed data. Details on enrolling in the program are enclosed in the personal notices. If you are a customer of Delta Dental of California, you are advised to be cautious with unsolicited communications, as your data may have been already shared with phishing actors, scammers, and other cybercriminals. Delta Dental’s case is the third largest MOVEit data breach, only behind Maximus (11 million) and Welltok (8.5 million).
Daily Brief Summary
Delta Dental of California experienced a data breach due to MOVEit Transfer software vulnerability, exposing personal information of nearly 7 million people.
A zero-day SQL injection flaw, CVE-2023-34362, was exploited, which allowed the Clop ransomware group to access thousands of organizations.
Unauthorized access to Delta Dental's system occurred between May 27 and May 30, 2023, with the breach confirmed following an investigation on June 6, 2023.
Compromised data includes names, financial account numbers, and credit/debit card information, including security codes.
Delta Dental is offering 24 months of free credit monitoring and identity theft protection services to impacted customers.
Impacted customers are advised to be vigilant against unsolicited communications that may lead to phishing or scams.
This incident ranks as the third-largest in a series of breaches involving MOVEit software, trailing behind incidents at Maximus and Welltok.