HackingVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHighContained
Pension Benefit Information, LLC
bd_223e8c30e3bd391d · schema v1 · pii pii-v1
Full breach record for Pension Benefit Information, LLC →Pension Benefit Information, LLC (PBI) notified the Delaware Attorney General of a security event involving MOVEit Transfer software. A threat actor exploited a zero-day vulnerability to access PBI's servers on May 29-30, 2023, and exfiltrated data including names, partial addresses, SSNs, and DOBs of 1,604 Delaware residents. PBI patched systems, engaged forensic specialists, and offered 24 months of credit monitoring via Kroll. Notification to residents began July 12, 2023.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_20a3b8416525341eVermont State AGfiled 2023-07-12(2d gap)Candidate
- bd_e732ff20c2386d79Vermont State AGfiled 2023-07-19(9d gap)Verified
- bd_4c50415a8827e689Oregon State AGfiled 2023-07-27(17d gap)Candidate
- bd_1885081c1d2bb691Hawaii State AGfiled 2023-07-28(18d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 32d gap
- bd_27f033748566ecf2New Hampshire State AGfiled 2023-08-08(29d gap)Verified
- bd_7bdc23aedd0d2aaaHawaii State AGfiled 2023-08-08(29d gap)Candidate
- bd_7632da10b2361b23New Hampshire State AGfiled 2023-08-11(32d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/07/Notice-of-Data-Event-PBI-DE.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 10, 2023
- Raw hash
- f4a6fe7bf53eab7dd486c4a545251faec6fed3dac907118b99d437748d71ae67
Reporting entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Victim entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Incident
- Discovered
- Jun 2, 2023
- Materiality determined
- —
- Notification sent
- Jul 12, 2023
- Affected individuals
- 1,604
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- providing written notice of this event to appropriate governmental regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(38 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.