DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitCapture Stored DataZero-DayData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedMulti-Stage ChainPIIIdentity (basic)Government IDHealth (basic)MediumContained

American National Group, LLC

bd_30aaf91c389f259b · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Aug 18, 2023

To disclose

Affected

Not disclosed

Confidence

79%

American National Group, LLC was affected by the MOVEit Transfer zero-day vulnerability (announced May 31, 2023) exploited by an unauthorized third party on May 28, 2023. Customer files containing names, SSNs, dates of birth, addresses, and medical treatment information were acquired. The company took MOVEit offline, engaged incident response professionals, and notified law enforcement. Affected individuals were offered 24-month Experian IdentityWorks credit monitoring.

Incident timeline

May 28, 2023

Begins

Aug 18, 2023

Filed

Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.