HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICPIILowContained
Athene Annuity and Life Company and its affiliates
bd_2122d1ad58be678c · schema v1 · pii pii-v1
Full breach record for Athene Annuity and Life Company and its affiliates →Athene Annuity and Life Company notified the California AG of a data breach involving its third-party vendor, Pension Benefit Information (PBI). PBI's MOVEit Transfer server was accessed by an unauthorized third party on May 29-30, 2023, exploiting a vulnerability disclosed by Progress Software on May 31, 2023. Data was downloaded from the server. Affected individuals' information included names and other data elements. PBI patched servers, investigated the incident, and is offering 12 months of identity monitoring through Kroll.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_0b2433a9bf13981dMaine State AGfiled 2023-07-20Verified
- bd_4774c894ba19f11eOregon State AGfiled 2023-07-20Verified
- bd_9def23da88b251ffWashington State AGfiled 2023-07-20Verified
- bd_a1e18d6a91a9c264California State AGfiled 2023-09-18(60d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 60d gap
- bd_a61e1b257e771444Oregon State AGfiled 2023-09-18(60d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570576
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 20, 2023
- Raw hash
- 83ed2bf4258252351e177e141e1cadcb969496a519a6164c5f51b276000d0b73
Reporting entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Victim entity
- Name
- Athene Annuity and Life Company and its affiliatesnorm: athene annuity and life company and its affiliates
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.