New York’s top financial regulator has fined Delta Dental Insurance Company and Delta Dental of New York $2.25 million after finding the companies failed to maintain adequate cybersecurity controls and delayed reporting a major data breach tied to the widespread MOVEit software hack.
The New York State Department of Financial Services said attackers exploited a zero-day vulnerability in MOVEit Transfer software in 2023 and gained unauthorized access to servers used by the companies to exchange files with customers, providers, business partners, and employees.
Regulators said the breach exposed a significant amount of consumer information, including Social Security numbers, driver’s license numbers, financial account information, insurance details, and patient health information.
The case adds to the long list of enforcement actions stemming from the MOVEit cyberattack campaign, which affected hundreds of organizations globally and became one of the most significant third party software breaches in recent years.
According to the consent order, Delta Dental’s affiliate identified suspicious activity and discovered a webshell installed on MOVEit servers on June 1, 2023, the same day Progress Software publicly disclosed the vulnerability. The companies shut down access to the platform, removed malicious files, deployed patches, and launched an investigation.
Investigators later determined that attackers had exfiltrated roughly 60,000 files between May 28 and May 30, 2023.
DFS said the companies violated New York cybersecurity regulations in several ways, including failing to maintain proper data retention controls and failing to establish sufficient incident response procedures tied to regulatory reporting obligations.
One of the more notable findings centered on file retention practices. MOVEit folders were configured with a default deletion period of 30 days, but the companies had extended retention periods for many folders and disabled retention settings entirely in some cases without formal policies governing those decisions. Regulators said most of the files stolen during the breach had been stored longer than the default retention period.
DFS also criticized the companies for waiting until Dec. 15, 2023 to notify the department about the incident, despite identifying evidence of unauthorized access months earlier. Under New York’s cybersecurity regulation, covered entities generally must notify regulators within 72 hours of determining a reportable cybersecurity event has occurred.
Acting Superintendent Kaitlin Asrow said the department’s cybersecurity regulation requires institutions to maintain “robust policies” to protect consumer information and said regulators will continue pursuing enforcement actions as cyber threats grow.
The consent order noted that the companies cooperated with the investigation and have continued remediation efforts.
.




