Delta Dental says data breach exposed info of 7M people
A major data breach at Delta Dental of California, linked to the MOVEit file transfer vulnerability, reportedly exposed personal and financial information — including improperly stored credit card security codes — for about 7 million people. Commenters argue this reflects systemic failures in data security and regulation: weak incentives for companies, overreliance on third-party vendors, delayed disclosure, and the routine offer of short-term credit monitoring instead of meaningful accountability. Many note growing “breach fatigue” among consumers and call for stricter statutory penalties, better payment architectures, and wider use of tools like credit freezes and tokenized payments.
Scope and Specifics of the Breach
- Breach tied to the MOVEit vulnerability; data was exfiltrated from Delta Dental of California, not all Delta Dental entities.
- Affected data reportedly includes names, financial account and credit/debit card numbers, and security codes.
- Several comments highlight that Delta Dental of California administers plans for federal employees and VA-recommended plans, raising concern about impact on sensitive populations.
- Some users note that employer-sponsored members often never gave Delta their card info, suggesting exposure may be concentrated among individual/retail customers.
PCI Compliance, CVV Storage, and Payment Practices
- Strong criticism that storing CVV/security codes violates PCI-DSS and common sense; some argue Delta should lose card-processing ability.
- Others note a deeper irony: MOVEit is marketed for PCI/HIPAA-type environments, so the “compliance” vendor being a breach vector is especially damning.
- Debate over how “secret” CVVs really are:
- One side: they’re not a true extra factor, just more digits.
- Counterpoint: rules against storing them reduce the attack surface and stop whole-database exfiltration from being immediately usable.
- Multiple commenters stress that the safest model is tokenization and avoiding storing raw card data at all.
Breach Frequency, Fatigue, and Personal Defenses
- Many assume nearly every American has already been in multiple breaches (Equifax, OPM, etc.).
- “Breach fatigue” is common: non-technical people, and some technical ones, largely shrug unless directly harmed.
- Personal mitigations discussed:
- Freezing credit at all three bureaus (though the process is described as painful and insecurely designed).
- Avoiding debit cards, using credit with alerts, virtual numbers, and quick-lock features.
- Accepting that card numbers will leak and focusing on monitoring and dispute mechanisms.
Accountability, Regulation, and Notification Delays
- Strong calls for statutory damages per exposed record, harsh fines, and even prison for egregious negligence.
- Some propose effectively “death sentences” for negligent data holders to force data minimization and user-controlled data stores.
- Many criticize the months-long delay between discovery (June) and public notification (late November), and claim this likely violates state notification laws.
- Widespread sentiment that companies face little real consequence, so poor security persists.
Broader Systemic Critiques
- Frustration that the payment system still relies on static card numbers instead of stronger cryptographic or banking-based systems.
- Some point to better models abroad (e.g., bank-app-based authorization) and gradual shifts like Apple/Google Pay and virtual numbers.
- Separate thread on dental insurance: mixed views, with some calling it a cartel-like “payment plan,” others defending it as genuine insurance with meaningful negotiated discounts.