DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedZero-DayIdentity (basic)Government IDPHIHealth (basic)MediumContained

American National Group, LLC

bd_1883ffcf0cd43386 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 31, 2023

Filed

Aug 9, 2023

To disclose

10 weeks

Affected

Not disclosed

Confidence

65%

American National Group, LLC experienced a data breach via a vulnerability in Progress Software's MOVEit Transfer application. An unauthorized third party accessed systems on May 28, 2023, exfiltrating customer data including names, SSNs, DOBs, addresses, and medical treatment info. The company took the app offline, engaged IR professionals, and notified law enforcement. Customers are offered 2 years of credit monitoring.

Incident timeline

undetected · 3 days
discovery → filing · 10 weeks / 70 days

May 28, 2023

Begins

May 31, 2023

Discovered

Aug 9, 2023

Filed

vs. sector median

on median

Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.