HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Transamerica Life Insurance Company
bd_40ec919e4e8f1a27 · schema v1 · pii pii-v1
Full breach record for Transamerica Life Insurance Company →Pension Benefit Information, LLC (PBI), a third-party vendor for Transamerica Life Insurance Company, disclosed a data breach involving the MOVEit Transfer software vulnerability. An unauthorized third party accessed PBI's MOVEit server on May 29-30, 2023, downloading data containing personal information (PII) of Transamerica policyholders. PBI patched servers, investigated, and offered 12 months of credit monitoring via Kroll. No identity theft or fraud has been confirmed.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_24dc3ee127f0580fDelaware State AGfiled 2023-07-28Verified by operator
- bd_e44dd39c1fbaba36Montana State AGfiled 2023-07-26(2d gap)Verified by operator
- bd_12a60db0c295b267California State AGfiled 2023-08-04(7d gap)Verified by operator
- bd_5a97af0225b216fdOregon State AGfiled 2023-08-10(13d gap)Verified by operator
Show 1 more filing ↓Show fewer ↑up to 16d gap
- bd_8f17c44e8a0bcc91Washington State AGfiled 2023-07-12(16d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/07/Transamerica-re-Individual-Notice-Template-Consumers-PBI.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 28, 2023
- Raw hash
- 451af43e96253d3265328399006f5cea9a5af4a58ee3068c0e3e229dd6924e4a
Reporting entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Victim entity
- Name
- Transamerica Life Insurance Companynorm: transamerica life insurance
- Domain
- tlic.transamerica.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.