Transamerica Life Insurance Company
bd_12a60db0c295b267 · schema v1 · pii pii-v1
Full breach record for Transamerica Life Insurance Company →Pension Benefit Information (PBI), a third-party service provider for Transamerica Life Insurance Company, experienced a data breach due to an exploited vulnerability in Progress Software's MOVEit Transfer software. An unauthorized third party accessed PBI's server on May 29-30, 2023, and downloaded data. PBI discovered the vulnerability on May 31, 2023. Affected data includes personal identifiable information such as names, addresses, and potentially Social Security numbers. PBI has patched servers, investigated the incident, and is offering 12 months of credit monitoring and identity restoration services through Kroll to affected individuals.
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_5a97af0225b216fdOregon State AGfiled 2023-08-10(6d gap)Verified by operator
- bd_24dc3ee127f0580fDelaware State AGfiled 2023-07-28(7d gap)Verified by operator
- bd_40ec919e4e8f1a27Delaware State AGfiled 2023-07-28(7d gap)Verified
- bd_e44dd39c1fbaba36Montana State AGfiled 2023-07-26(9d gap)Verified by operator
Show 1 more filing ↓Show fewer ↑up to 23d gap
- bd_8f17c44e8a0bcc91Washington State AGfiled 2023-07-12(23d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571343
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 4, 2023
- Raw hash
- b70bfadfd55fcf381db0d31f13c87a98cc7e14d2af15a671d171ba960e356f53
Reporting entity
- Name
- Transamerica Life Insurance Companynorm: transamerica life insurance
- Domain
- tlic.transamerica.com
Victim entity
- Name
- Transamerica Life Insurance Companynorm: transamerica life insurance
- Domain
- tlic.transamerica.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 9 weeks(65 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.