HackingVulnerability ExploitData ExfiltratedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Transamerica Life Insurance Company
bd_24dc3ee127f0580f · schema v1 · pii pii-v1
Full breach record for Transamerica Life Insurance Company →Pension Benefit Information, LLC (PBI), a third-party service provider for Transamerica Life Insurance Company, disclosed a data breach involving the MOVEit Transfer software vulnerability exploited by an unauthorized third party. The incident occurred on May 29-30, 2023, resulting in the unauthorized download of data containing personal information (identity_basic, identity_government). PBI patched servers, conducted investigations, and offered 12 months of credit monitoring via Kroll. No identity theft or fraud has been indicated.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_40ec919e4e8f1a27Delaware State AGfiled 2023-07-28Verified
- bd_e44dd39c1fbaba36Montana State AGfiled 2023-07-26(2d gap)Verified by operator
- bd_12a60db0c295b267California State AGfiled 2023-08-04(7d gap)Verified by operator
- bd_5a97af0225b216fdOregon State AGfiled 2023-08-10(13d gap)Verified by operator
Show 1 more filing ↓Show fewer ↑up to 16d gap
- bd_8f17c44e8a0bcc91Washington State AGfiled 2023-07-12(16d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/07/Transamerica-re-Individual-Notice-Template-Consumers-PBI.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 28, 2023
- Raw hash
- cf74e2520cfad2b6d87938e7002a2209c7239e8b7b03f567ea659e62c2ad73ee
Reporting entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Victim entity
- Name
- Transamerica Life Insurance Companynorm: transamerica life insurance
- Domain
- tlic.transamerica.com
Incident
- Discovered
- May 29, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.