Welltok, a US health services company, began notifying affected individuals on 17 November 2023 following exploitation of the MOVEit Transfer vulnerability filed at 23-0601. The initial notification covered approximately 8.5 million people, and the company reported discovering the compromise on 26 July 2023.
Reported data categories include names, contact details and, for some individuals, social security numbers, Medicare or Medicaid identifiers and health insurance information. Subsequent reporting put the final victim count substantially higher, at around 14.76 million.
The Number Moved, As Numbers Do
An initial notification figure is not a measurement of an incident. It is a measurement of how far a review had progressed on the day a deadline required a filing.
The corpus files the same movement at 24-0620, where the Change Healthcare count took eleven months to settle, and at 26-0526, where an initial figure was later revised. Anyone comparing incidents by their headline numbers is comparing review timetables as much as harm.
Patched And Compromised Anyway
Reporting notes that Welltok had installed published patches promptly when Progress made them available. That is consistent with the campaign at 23-0601 being a zero-day: exploitation ran before a fix existed.
This is the file to point at when patching discipline is offered as the answer. It is necessary, it was present here, and it was not sufficient — the same conclusion the corpus reaches at 25-1216 and 24-0110.
Three Removes From The Person
The affected individuals had a relationship with a health plan. The plan had a relationship with Welltok. Welltok had a relationship with a file transfer product. The vulnerability was in the fourth party.
Together with Maximus at 23-0728, this file is why the corpus can describe the MOVEit campaign’s downstream shape without ever asserting a total for it.
Built on contemporaneous reporting of Welltok’s notifications and of the revised victim count. The 8,493,379 initial figure, the 26 July 2023 discovery date and the data categories are as reported from the company’s notifications. The later figure of approximately 14.76 million is from subsequent reporting of updated filings; both are carried because the movement between them is the point of the file. The attribution of the underlying campaign to Cl0p rests on the CISA/FBI advisory cited at 23-0601. Graded high. Corrections: corrections@forensicpost.com.
- Welltok data breach exposes data of 8.5 million US patientsBleepingComputer
- Welltok Data Breach Victim Count Rises to 14.76 MillionHIPAA Journal