FEDERALItem 8.01 · voluntaryHackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICCriticalContained
F&G Annuities & Life, Inc.
bd_26a892c4941e140b · schema v1 · pii pii-v1
Full breach record for F&G Annuities & Life, Inc. →F&G Annuities & Life, Inc. disclosed a cybersecurity incident involving third-party vendor PBI Research Services on June 30, 2023. PBI was affected by a zero-day vulnerability in the MOVEit file transfer system. The incident exposed personal information, including Social Security numbers and dates of birth, for approximately 873,000 F&G policyholders and customers. F&G is providing credit monitoring and identity theft restoration services to affected individuals. The incident did not affect F&G's internal systems.
SEC clockMateriality determined Jun 30, 2023 → Filed Jun 30, 20230d ✓ SEC 4-day OK≤1 day discovery → filing
⚠ filing dateThe stored discovery date equals the regulator filing date, so no genuine detection date was captured.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed873,000 affectedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1934850/000193485023000046/
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 30, 2023
- Raw hash
- 486efd8e7018904de02c32fa455263835cb3fcb40e2503f4d7504da639060f44
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- F&G Annuities & Life, Inc.norm: f g annuities life
- SEC CIK
- 0001934850
Victim entity
- Name
- F&G Annuities & Life, Inc.norm: f g annuities life
- SEC CIK
- 0001934850
Incident
- Discovered
- Jun 30, 2023
- Materiality determined
- Jun 30, 2023
- Notification sent
- —
- Affected individuals
- 873,000
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Third party
- via PBI Research Services
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- filing dateThe stored discovery date equals the regulator filing date, so no genuine detection date was captured.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jun 30, 2023→ Filed: Jun 30, 20230d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.