MalwareRansomwareData ExfiltratedData EncryptedSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICLowResolved
The Northwestern Mutual Life Insurance Company
bd_272a1b1cde119499 · schema v1 · pii pii-v1
Full breach record for The Northwestern Mutual Life Insurance Company →Northwestern Mutual Life Insurance Company disclosed a ransomware incident affecting its third-party service provider, Infosys McCamish Systems (IMS). Unauthorized access and data acquisition occurred between October 29 and November 2, 2023. IMS systems were encrypted. Northwestern Mutual's internal systems were not compromised. Affected individuals were offered 24 months of identity monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_286b55f499b42ac8Maine State AGfiled 2024-06-27Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-587635
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 27, 2024
- Raw hash
- ca82d8f09574d55e401f34d7ac8b4d87080665ae47740b4708505ab3e360a161
Reporting entity
- Name
- INFOSYS MCCAMISH SYSTEMS, LLCnorm: infosys mccamish
Victim entity
- Name
- The Northwestern Mutual Life Insurance Companynorm: the northwestern mutual life insurance
- Domain
- northwesternmutual.com
Incident
- Discovered
- Nov 2, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Third party
- via Infosys McCamish Systems, LLC
Compliance
- Time to disclose
- 34 weeks(238 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.