HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
Sun Life Financial
bd_3d34eccb54cb5382 · schema v1 · pii pii-v1
Full breach record for Sun Life Financial →Sun Life Financial reported a data breach affecting California residents via a third-party software vulnerability in Progress Software's MOVEit Transfer. An unauthorized third party accessed Pension Benefit Information, LLC's (PBI) MOVEit server on May 29-30, 2023, and downloaded data including names. PBI patched servers, investigated, and offered 24 months of credit monitoring. This is a supplemental notice.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_16876df7363dddd3Maine State AGfiled 2023-11-06Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-576152
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 6, 2023
- Raw hash
- 24ed20c43f221c0b032a791a203a88037b3f2025deedd64129f9eaa945e02768
Reporting entity
- Name
- Sun Life Financialnorm: sun life financial
- Domain
- sunlifedistributors.com
Victim entity
- Name
- Sun Life Financialnorm: sun life financial
- Domain
- sunlifedistributors.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.