HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Pension Benefit Information, LLC
bd_5a81a9b3803e493c · schema v1 · pii pii-v1
Full breach record for Pension Benefit Information, LLC →Pension Benefit Information, LLC (PBI) disclosed a data breach involving the MOVEit Transfer software vulnerability exploited in May 2023. Unauthorized third parties accessed PBI servers on May 29-30, 2023, downloading data containing names and government identifiers. PBI patched systems, investigated, and offered 24 months of credit monitoring. No identity theft was confirmed.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_31eb3a86b455ca2aCalifornia State AGfiled 2023-08-24(1d gap)Verified
- bd_88a232a96ae8d0e9New Hampshire State AGfiled 2023-08-24(1d gap)Verified
- bd_f52c76855c9e670bNew Hampshire State AGfiled 2023-08-24(1d gap)Verified
- bd_ed5751101a0d93eeVermont State AGfiled 2023-08-25(2d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 40d gap
- bd_bc42d7fee9bd036cMaine State AGfiled 2023-08-16(7d gap)Candidate
- bd_8a9b6ba4c65dda36Delaware State AGfiled 2023-07-28(26d gap)Candidate
- bd_eb47f1a922c8d8ddDelaware State AGfiled 2023-07-17(37d gap)Candidate
- bd_729ad9694adf695eNew Hampshire State AGfiled 2023-07-14(40d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/09/ELN-18541-PBI-Longevity-Portal-2-Ad-CM-2y-Consumer-r2prf.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 23, 2023
- Raw hash
- 6d3db3478323506adc35830868e2d2ab7ec92d243ae8d7d0c7ffe396a78d8c5b
Reporting entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Victim entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.