Desk live·
ForensicPost
Breaches/Healthcare/File 23-1117

Welltok Notified 8.5 Million People Over MOVEit, Then the Number Nearly Doubled

A health services company that had installed the patches told 8.5 million people their data was taken. The count later rose past fourteen million — which is the ordinary behaviour of a breach figure, and the reason this database treats early numbers as provisional.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetWelltok
ActorCl0p
S. Rosler10 min readConfidence: high2 sources reviewed

Welltok, a US health services company, began notifying affected individuals on 17 November 2023 following exploitation of the MOVEit Transfer vulnerability filed at 23-0601. The initial notification covered approximately 8.5 million people, and the company reported discovering the compromise on 26 July 2023.

Reported data categories include names, contact details and, for some individuals, social security numbers, Medicare or Medicaid identifiers and health insurance information. Subsequent reporting put the final victim count substantially higher, at around 14.76 million.

The Number Moved, As Numbers Do

An initial notification figure is not a measurement of an incident. It is a measurement of how far a review had progressed on the day a deadline required a filing.

The corpus files the same movement at 24-0620, where the Change Healthcare count took eleven months to settle, and at 26-0526, where an initial figure was later revised. Anyone comparing incidents by their headline numbers is comparing review timetables as much as harm.

Patched And Compromised Anyway

Reporting notes that Welltok had installed published patches promptly when Progress made them available. That is consistent with the campaign at 23-0601 being a zero-day: exploitation ran before a fix existed.

This is the file to point at when patching discipline is offered as the answer. It is necessary, it was present here, and it was not sufficient — the same conclusion the corpus reaches at 25-1216 and 24-0110.

Three Removes From The Person

The affected individuals had a relationship with a health plan. The plan had a relationship with Welltok. Welltok had a relationship with a file transfer product. The vulnerability was in the fourth party.

Together with Maximus at 23-0728, this file is why the corpus can describe the MOVEit campaign’s downstream shape without ever asserting a total for it.

How we reported this

Built on contemporaneous reporting of Welltok’s notifications and of the revised victim count. The 8,493,379 initial figure, the 26 July 2023 discovery date and the data categories are as reported from the company’s notifications. The later figure of approximately 14.76 million is from subsequent reporting of updated filings; both are carried because the movement between them is the point of the file. The attribution of the underlying campaign to Cl0p rests on the CISA/FBI advisory cited at 23-0601. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Welltok data breach exposes data of 8.5 million US patientsBleepingComputer
  2. Welltok Data Breach Victim Count Rises to 14.76 MillionHIPAA Journal
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary