HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTCVE-2023-34362MediumContained
AETNA LIFE INSURANCE COMPANY
bd_5cff8a74b54803d1 · schema v1 · pii pii-v1
Full breach record for AETNA LIFE INSURANCE COMPANY →Pension Benefit Information, LLC (PBI) disclosed a data breach involving MOVEit Transfer software exploited by an unauthorized third party on May 29-30, 2023. The incident affected data belonging to clients, including Aetna Life Insurance. PBI patched servers, investigated, and offered 12 months of credit monitoring. Data potentially exposed included names and government identifiers.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_126a641beec748aaMaine State AGfiled 2023-09-12(2d gap)Verified
- bd_5528b9ad41d618a0Washington State AGfiled 2023-09-08(6d gap)Verified
- bd_8ddaa57f2866b4ffMontana State AGfiled 2023-09-07(7d gap)Candidate
- bd_db05396264958227Maine State AGfiled 2023-12-01(78d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/09/eln-18540-pbi-longevity-portal-2-ad-cm-1y-consumer-r2prf.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 14, 2023
- Raw hash
- ae6107adc3664b094dfeef89b9de5e35561c5b03602711d47d0539e588ad8d59
Reporting entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Victim entity
- Name
- AETNA LIFE INSURANCE COMPANYnorm: aetna life insurance
Incident
- Discovered
- May 29, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
- CVE references
Compliance
- Time to disclose
- 15 weeks(108 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.