DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedZero-DayIdentity (basic)Government IDHealth (basic)BiometricFinancial accountMediumContained

PAN-AMERICAN LIFE INSURANCE GROUP, INC.

bd_5344622ba4da78bb · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Dec 4, 2023

To disclose

Affected

Not disclosed

Linked

12 filings

Confidence

66%
Full breach record for PAN-AMERICAN LIFE INSURANCE GROUP, INC.5 incidents on file

Pan-American Life Insurance Company (PALIC) notified California residents of a data breach involving the MOVEit Transfer application by Progress Software. An unauthorized third party exploited a previously unknown vulnerability in MOVEit to exfiltrate files containing personal information, including names, addresses, SSNs, dates of birth, driver's license numbers, medical information, biometric data, and financial account details. The breach occurred on May 28, 2023. PALIC stopped using MOVEit, secured other systems, engaged cybersecurity experts, and notified law enforcement. Affected individuals are offered 24 months of Experian IdentityWorks.

Leak gap clock Leak >180d
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.

Incident timeline

May 28, 2023

Begins

Dec 4, 2023

Filed

This filing is one of 12 about the same incident.View merged incident
A leak claim by dispossessor about this victim predates this filing by 413 days.View originating leak claim

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (9) · sorted by filing gap

Show 5 more filingsup to 337d gap

Showing first 10 of 11 linked disclosures.

Filing propagation · 10 filings · 9 states

View merged incident ↗

Pattern: first filing Jan 1 (IL), last Dec 7 (NH) — a 340-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Cascade drawn from the first 10 linked disclosures of 11 — the full spread may be wider.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.