HackingVulnerability ExploitStolen CredentialsData ExfiltratedData EncryptedSupply Chain (3P Vendor)Customer Data InvolvedMulti-Stage ChainTargetedPIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCVE-2023-34362CriticalContained
jackson.com
bd_23c03d25d6131fce · schema v1 · pii pii-v1
Full breach record for jackson.com →Jackson National Life Insurance Company reported a third-party data breach involving vendor Pension Benefit Information (PBI). Attackers exploited a vulnerability in PBI's MOVEit file-transfer software (CVE-2023-34362) to exfiltrate customer data, including names, SSNs, and financial account details. Approximately 700,000 to 800,000 individuals were affected. Jackson notified affected consumers and offered credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_d95ca6ae977c3c0aLeak Sitecl0pfiled 2023-06-29(28d gap)Candidate
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/JacksonNationalLifeInsuranceCompany.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 27, 2023
- Raw hash
- 5fd875c0f48be44b84340fc003b3cdc4553bddffbcef2c58c02757ac9156f06f
Reporting entity
- Name
- jackson.comnorm: jacksoncom
- Domain
- jackson.com
Victim entity
- Name
- jackson.comnorm: jacksoncom
- Domain
- jackson.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- Jun 26, 2023
- Notification sent
- —
- Affected individuals
- 800,000
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 ChannelT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with South Carolina Department of Consumer Affairs
- Third party
- via Pension Benefit Information, LLCvendor
- Initial access
- exploit_public_facing
- CVE references
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.