UNUM GROUP
bd_5fd3c14b044d2a09 · schema v1 · pii pii-v1
Full breach record for UNUM GROUP →12 incidents on fileUnum Group notified South Carolina residents of a cybersecurity incident involving its MOVEit Transfer application (Progress Software). Unauthorized access occurred May 31-June 1, 2023, exploiting a vulnerability to exfiltrate data including names, SSNs, medical info, and financial data. Unum detected suspicious activity on June 1, 2023, and began notifying individuals on August 3, 2023. Response included taking the system offline, patching, and offering 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 31, 2023
Begins
Jun 1, 2023
Discovered
Sep 19, 2023
Filed
vs. sector median
+7 wks slower
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- California State AGbd_60e06d7b099885312023-09-19Verified
- Massachusetts State AGbd_d63872c90f649d742023-09-19Verified
- Oregon State AGbd_be1b59e27105faaa2023-09-05 · +14dVerified
- Washington State AGCL0Pbd_e9863c8671e00ee82023-08-21 · +29dVerified
Show 2 more filings ↓Show fewer ↑up to 47d gap
- Indiana State AGbd_7e4b64e3b2796a5e2023-08-03 · +47dCandidate
- HHS OCRbd_daff25a5bf2dc4eb2023-08-03 · +47dCandidate
Filing propagation · 7 filings · 7 states
View merged incident ↗Pattern: first filing Aug 3 (IN), last Sep 19 (SC) — a 47-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.