HackingFinancial ServicesFinanceVulnerability ExploitCapture Stored DataZero-DayData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedMulti-Stage ChainPIIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
American National Group, LLC
bd_30aaf91c389f259b · schema v1 · pii pii-v1
American National Group, LLC was affected by the MOVEit Transfer zero-day vulnerability (announced May 31, 2023) exploited by an unauthorized third party on May 28, 2023. Customer files containing names, SSNs, dates of birth, addresses, and medical treatment information were acquired. The company took MOVEit offline, engaged incident response professionals, and notified law enforcement. Affected individuals were offered 24-month Experian IdentityWorks credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572058
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 18, 2023
- Raw hash
- 4efa3c1907200aeaf2caa314ed2776a075cd0caa87a18168e07d1553e42f42e9
Reporting entity
- Name
- American National Insurance Companynorm: american national insurance
Victim entity
- Name
- American National Group, LLCnorm: american national group
- Industry
- Financial Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated CollectionT1074 Data Staged
- Threat actor
- External
- Regulator citations
- Notified California Attorney GeneralNotified law enforcement and cooperating with their investigation
- Third party
- via Progress Software Corporation
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.