MalwarePhishingRansomwareData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALMediumContained
PAN-AMERICAN LIFE INSURANCE GROUP, INC.
bd_4c420d6a8894a3ff · schema v1 · pii pii-v1
Full breach record for PAN-AMERICAN LIFE INSURANCE GROUP, INC. →Pan-American Life Insurance Group experienced a data security incident detected on February 19, 2021, following a phishing attempt that resulted in malware installation. Unauthorized access occurred on February 16, 2021. The attacker exfiltrated personal information including names, addresses, dates of birth, and for a small percentage of individuals, more sensitive data such as Social Security numbers. The company took systems offline, engaged forensic experts, and offered credit monitoring to affected policyholders and beneficiaries.
California clockDiscovered Feb 19, 2021 → Notified Mar 11, 202120d ✓ CA 60-day OK20 days discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_6ad9d6e594b013d2Maine State AGfiled 2021-03-11Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539040
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 11, 2021
- Raw hash
- a5833e5ca000c4361a73d22fcea192d041b1c385f320024bcbcfdb2f34c2cff4
Reporting entity
- Name
- PAN-AMERICAN LIFE INSURANCE GROUP, INC.norm: pan american life insurance
- Domain
- palig.com
Victim entity
- Name
- PAN-AMERICAN LIFE INSURANCE GROUP, INC.norm: pan american life insurance
- Domain
- palig.com
Incident
- Discovered
- Feb 19, 2021
- Materiality determined
- —
- Notification sent
- Mar 11, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 20d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 19, 2021→ Notified: Mar 11, 202120d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.