← Virgin Pulse

2023 Welltok (Virgin Pulse) — MOVEit Transfer compromise; multi-tenant health-plan notifications

2023 14.8M records affected Share on X

Data compromised

Participant names, addresses, DOB, member IDs, SSN-class identifiers, and plan or wellness-program metadata per downstream notices

Technical writeup

Welltok, Inc.—the wellness-engagement vendor later positioned under Virgin Pulse—ran a Progress MOVEit Transfer instance that Clop-affiliated actors exploited in the late-May 2023 wave. Exfiltration from Welltok’s server drove a cascading HIPAA notification program affecting dozens of health-plan and employer clients; aggregated HHS-oriented reporting (e.g., HIPAA Journal rollups) cited on the order of 14.76 million individuals, with earlier press waves often citing roughly eight million, reflecting ongoing regulator tallies. Data elements varied by program but commonly included demographic, contact, and health-plan or clinical-administrative fields.

Root cause

CVE-class exploitation of MOVEit Transfer enabling mass exfiltration (Clop campaign context)

References