HackingVulnerability ExploitZero-DayData ExfiltratedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
AMERICAN NATIONAL GROUP INC.
bd_0a85b0d237e54f9f · schema v1 · pii pii-v1
Full breach record for AMERICAN NATIONAL GROUP INC. →American National Group, LLC notified Delaware AG of a data breach involving its MOVEit Transfer application. An unauthorized third party exploited a previously unknown vulnerability (zero-day) in the software to access systems on May 28, 2023, exfiltrating customer personal information including names, SSNs, DOBs, addresses, and medical treatment details. American National took the application offline, engaged third-party advisors, and notified law enforcement. Affected individuals were offered two years of complimentary credit monitoring via Experian.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_80f0bc4126269b26Delaware State AGfiled 2023-08-10(4d gap)Candidate
- bd_f92f2bd656843776Delaware State AGfiled 2023-08-10(4d gap)Verified
- bd_1883ffcf0cd43386California State AGfiled 2023-08-09(5d gap)Candidate
- bd_8def1b12f7e1a600Oregon State AGfiled 2023-08-09(5d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/09/American-National-Sample-Notification-Letter-August-11-2023-V2.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 14, 2023
- Raw hash
- 6b7b28001b8a24cf81ac643b29cc0ad2c59b8df4a097326b771cf0b03dec8411
Reporting entity
- Name
- AMERICAN NATIONAL GROUP INC.norm: american national
Victim entity
- Name
- AMERICAN NATIONAL GROUP INC.norm: american national
Incident
- Discovered
- May 28, 2023
- Materiality determined
- —
- Notification sent
- Aug 11, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- notified law enforcement and are cooperating with their investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(78 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.