New York regulators fined Delta Dental $2.25 million after finding the insurer violated state cybersecurity rules in its handling of the 2023 MOVEit Transfer breach. Attackers linked to the Clop cybercrime group exploited a zero-day SQL injection flaw in Progress Software’s file transfer platform, accessed Delta Dental’s environment between May 27 and May 30, 2023, and exfiltrated about 60,000 files containing sensitive personal, financial, and health information. Delta Dental said the incident affected nearly 7.1 million customers, and breach notices offered affected individuals 24 months of identity monitoring and identity theft protection services.
The New York Department of Financial Services said Delta Dental discovered a web shell on its MOVEit servers on June 1, 2023 but did not notify regulators until Dec. 15, 2023, far beyond the state’s 72-hour reporting requirement. Investigators also found the company lacked adequate written incident response and reporting plans and had weak data retention and secure disposal practices, with some MOVEit folders retaining data longer than the platform’s default 30-day period or having retention disabled entirely. The April 29 consent order imposed the monetary penalty on Delta Dental of New York and Delta Dental Insurance and did not require additional corrective actions beyond compliance with the settlement.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
A consent order dated 2026-04-29 between the New York Department of Financial Services, Delta Dental of New York, and Delta Dental Insurance imposed a $2.25 million penalty over the company's handling of the 2023 MOVEit breach. Regulators said Delta Dental violated state cybersecurity rules on data retention, secure disposal, incident response planning, and timely notification.
Delta Dental notified New York regulators on 2023-12-15, more than six months after identifying the web shell on June 1. New York later said this exceeded the state's 72-hour cyber incident reporting requirement.
On 2023-11-27, Delta Dental determined that the incident affected the recipient's personal information. The breach notice also states that affected individuals were offered 24 months of identity monitoring and identity theft protection through Kroll.
On 2023-07-06, Delta Dental determined that unauthorized access to information stored on its MOVEit platform had occurred. This marked the company's confirmation of the breach following its initial June 1 discovery.
On 2023-06-01, Delta Dental identified a web shell on its MOVEit servers and learned of the incident. The company then disabled access to MOVEit, removed malicious files, applied patches, reset administrative passwords, enhanced monitoring, engaged forensic experts, and notified law enforcement.
Delta Dental disclosed that unauthorized actors exploited a previously unknown MOVEit Transfer vulnerability and accessed and acquired company information without authorization between May 27 and May 30, 2023. Reporting on the incident ties this activity to the broader Clop-linked MOVEit mass exploitation campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
5 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceismg-cdn.nyc3.cdn.digitaloceanspaces.com
Open sourceoag.ca.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.