HackingVulnerability ExploitCapture Stored DataZero-DayData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICCVE-2023-34362LowContained
MILLIMAN, INC.
bd_0784ee17d069ca5f · schema v1 · pii pii-v1
Full breach record for MILLIMAN, INC. →Milliman, Inc. notified the NH AG of a data breach involving its third-party vendor, Pension Benefit Information, LLC (PBI). PBI's MOVEit Transfer software was exploited via CVE-2023-34362 (zero-day) on May 29-30, 2023. An unauthorized actor downloaded data belonging to 335 New Hampshire residents. Milliman stopped data transfers to PBI and is enhancing vendor security. PBI patched the vulnerability and offered 24 months of credit monitoring.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_ef7ad7a4aedf79b1Maine State AGfiled 2023-08-18(1d gap)Verified
- bd_5fb2b809a54c9f68California State AGfiled 2023-08-14(3d gap)Verified
- bd_847189c2c427ed3bMaine State AGfiled 2023-08-14(3d gap)Candidate
- bd_b71e461fa51aa4b2Washington State AGfiled 2023-08-14(3d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 3d gap
- bd_c290a9c83b4262b5Oregon State AGfiled 2023-08-14(3d gap)Verified
- bd_d1cb5766b2805d52Idaho State AGfiled 2023-08-14(3d gap)Verified
- bd_efdfa8d0534820d3Montana State AGfiled 2023-08-14(3d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/milliman-20230817.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 17, 2023
- Raw hash
- 6e6831f52a383d04b21e48c70f4de15720af8ea379e55e834e74dd0e37c32d67
Reporting entity
- Name
- MILLIMAN, INC.norm: milliman
Victim entity
- Name
- MILLIMAN, INC.norm: milliman
Incident
- Discovered
- May 31, 2023
- Materiality determined
- Jul 21, 2023
- Notification sent
- Aug 14, 2023
- Affected individuals
- 335
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with New Hampshire Attorney General Consumer Protection Bureau
- Third party
- via Pension Benefit Information, LLC
- Initial access
- exploit_public_facing
- CVE references
Compliance
- Time to disclose
- 11 weeks(78 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.