Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Delta Dental Says Data Breach Exposed 7 Million Customers

Delta Dental of California says over 6.9 million individuals were impacted by a data breach caused by the MOVEit hack.

Dental insurance giant Delta Dental of California is informing more than 6.9 million individuals that their personal information was compromised as result of the MOVEit hacking incident.

In notification letters it started sending out last week to the impacted individuals, the dentist network says the attackers stole names, addresses, Social Security numbers, passport numbers, state identification numbers (such as driver’s license numbers), financial account details, tax identification numbers, and health insurance and health information.

The information was compromised after the Cl0p ransomware gang exploited a vulnerability in the MOVEit Transfer managed file transfer application to tap into the data organizations were transferring using the service.

In an incident notice posted on its website, Delta Dental says it was alerted of the MOVEit hack on June 1, and that its investigation determined in July that the attackers had access to its information on the service between May 27 and May 30.

“On November 27, 2023, the company determined what personal information was affected and to whom it belonged,” Delta Dental says in the written notification sent to the affected individuals, a copy of which was submitted to the Maine Attorney General’s Office.

The company also outlines the steps taken to contain and remediate the incident and urges the impacted individuals to remain vigilant of any suspicious activity on their accounts, while offering them free identity monitoring services.

“Our investigation found that approximately 7 million individuals were impacted. In addition to our own investigation, we have also notified law enforcement of the incident and have been cooperating with them since,” the company says.

Delta Dental offers individual and group dental insurance plans, with more than 85 million people across the US using its services. The company says it has the largest network of dentists in the country.

Advertisement. Scroll to continue reading.

According to cybersecurity firm Emsisoft, a total of more than 2,680 organizations are confirmed to have been affected by the MOVEit hack, with the number of impacted individuals being close to 91 million.

With more than 6.9 million people impacted, Delta Dental’s MOVEit data breach is the third largest. The top two spots are taken by government services provider Maximus, with 11 million affected individuals, and healthcare SaaS provider Welltok, with approximately 8.5 million.

“The disclosure of Delta Dental’s impacted patients highlights the urgent need for cybersecurity defenses that extend beyond IT infrastructures, encompassing third-party vendors. Continuous evaluation of one’s security posture using an automated security platform will help identify threats in real-time, allowing organizations that manage the sensitive data of millions to mitigate cyber threats,” Swimlane security architect Nick Tausek said in an emailed comment.

Related: 185,000 Individuals Impacted by MOVEit Hack at Car Parts Giant AutoZone

Related: Yamaha Motor Confirms Data Breach Following Ransomware Attack

Related: Evidence Suggests Ransomware Group Knew About MOVEit Zero-Day Since 2021

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Gain valuable insights from industry professionals who will help guide you through the intricacies of industrial cybersecurity.

Register

Join us for an in depth exploration of the critical nature of software and vendor supply chain security issues with a focus on understanding how attacks against identity infrastructure come with major cascading effects.

Register

Expert Insights

Related Content

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

CISO Strategy

Okta is blaming the recent hack of its support system on an employee who logged into a personal Google account on a company-managed laptop.

Data Breaches

Sony shares information on the impact of two recent unrelated hacker attacks carried out by known ransomware groups. 

Data Breaches

A group of hackers has leaked Atlassian employee records and floorplans, information that was obtained from third-party workplace platform Envoy.

Data Breaches

KFC and Taco Bell parent company Yum Brands says personal information was compromised in a January 2023 ransomware attack.

Data Breaches

AT&T is notifying millions of wireless customers that their CPNI was compromised in a data breach at a third-party vendor.