HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
PBI Research Services
bd_56bf16939535bbe5 · schema v1 · pii pii-v1
Full breach record for PBI Research Services →Pension Benefit Information, LLC notified California residents that an unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer software to access and download data from PBI's servers on May 29-30, 2023. The incident was discovered on May 31, 2023. Affected data includes names and other data elements. PBI patched servers, investigated the scope, and is offering identity monitoring services through Kroll.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572330
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 24, 2023
- Raw hash
- 9bd95d4e7bc8482e8674fe51a8bb86f42bfb06713dd5c846df53f34c3de09914
Reporting entity
- Name
- NTT DATA Americas, Inc. on behalf of PBI Research Servicesnorm: ntt data americas inc on behalf of pbi research
Victim entity
- Name
- PBI Research Servicesnorm: pbi research
- Domain
- pbinfo.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 12 weeks(85 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.