HackingVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedZero-DayIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
AMERICAN NATIONAL GROUP INC.
bd_1883ffcf0cd43386 · schema v1 · pii pii-v1
Full breach record for AMERICAN NATIONAL GROUP INC. →American National Group, LLC experienced a data breach via a vulnerability in Progress Software's MOVEit Transfer application. An unauthorized third party accessed systems on May 28, 2023, exfiltrating customer data including names, SSNs, DOBs, addresses, and medical treatment info. The company took the app offline, engaged IR professionals, and notified law enforcement. Customers are offered 2 years of credit monitoring.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_8def1b12f7e1a600Oregon State AGfiled 2023-08-09Verified
- bd_80f0bc4126269b26Delaware State AGfiled 2023-08-10(1d gap)Candidate
- bd_f92f2bd656843776Delaware State AGfiled 2023-08-10(1d gap)Verified
- bd_0a85b0d237e54f9fDelaware State AGfiled 2023-08-14(5d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571563
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 9, 2023
- Raw hash
- 3ef177b7be09af74f320ceccc08593004d0c3e4eac5de3b8cce37beedab36422
Reporting entity
- Name
- AMERICAN NATIONAL GROUP INC.norm: american national
Victim entity
- Name
- AMERICAN NATIONAL GROUP INC.norm: american national
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software Corporation
- Initial access
- supply_chain
Compliance
- Time to disclose
- 10 weeks(70 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.