PAN-AMERICAN LIFE INSURANCE GROUP, INC.
bd_5344622ba4da78bb · schema v1 · pii pii-v1
Full breach record for PAN-AMERICAN LIFE INSURANCE GROUP, INC. →Pan-American Life Insurance Company (PALIC) notified California residents of a data breach involving the MOVEit Transfer application by Progress Software. An unauthorized third party exploited a previously unknown vulnerability in MOVEit to exfiltrate files containing personal information, including names, addresses, SSNs, dates of birth, driver's license numbers, medical information, biometric data, and financial account details. The breach occurred on May 28, 2023. PALIC stopped using MOVEit, secured other systems, engaged cybersecurity experts, and notified law enforcement. Affected individuals are offered 24 months of Experian IdentityWorks.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_306f54f2b1d4428cWashington State AGfiled 2023-12-04Verified
- bd_41d152391339bf42HHS OCRfiled 2023-12-04Candidate
- bd_a6c419df4cc08783HHS OCRfiled 2023-12-04Verified
- bd_dde2d990b55f9a62Maine State AGfiled 2023-12-04Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-577420
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 4, 2023
- Raw hash
- 102e4eb34d0c5f0869d276e57131e737b5175613157fbb534f473740a1a8524c
Reporting entity
- Name
- PAN-AMERICAN LIFE INSURANCE GROUP, INC.norm: pan american life insurance
- Domain
- palig.com
Victim entity
- Name
- PAN-AMERICAN LIFE INSURANCE GROUP, INC.norm: pan american life insurance
- Domain
- palig.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Dec 4, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICBIOMETRICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement authorities
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Compliance flags
- Leak >180d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.