A $2.25 million fine has been imposed on Delta Dental by New York for its handling of a 2023 cyberattack exploiting a zero-day vulnerability in Progress Software's MOVEit file transfer application. The attack, which occurred over Memorial Day, affected thousands of organizations, including Delta Dental, due to the automated nature of the exploit. Investigators found that Delta Dental violated state cyber regulations in its response to the incident. The zero-day exploit meant that the vulnerability was being utilized by attackers before a patch was available, putting defenders at an immediate disadvantage1. This incident highlights the importance of proactive cybersecurity measures, as the lack of a patch left organizations vulnerable to attack. The fine serves as a reminder to organizations to prioritize compliance with state cyber regulations to mitigate the risk of such incidents. So what matters to practitioners is that this incident underscores the need for swift and effective incident response to minimize the impact of zero-day exploits.
NY Fines Delta Dental $2.25M Over 2023 MOVEit Hack
⚠️ Critical Alert
Why This Matters
Zero-day exploitation means the vulnerability is being used before patches exist — defenders are already behind.
References
- Bank Info Security. (2026, May 4). NY Fines Delta Dental $2.25M Over 2023 MOVEit Hack. Bank Info Security. https://www.bankinfosecurity.com/ny-fines-delta-dental-225m-over-2023-moveit-hack-a-31586
Original Source
Bank Info Security
Read original →