HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICPIILowContained
GENWORTH NORTH AMERICA CORPORATION
bd_6082bee62aaee255 · schema v1 · pii pii-v1
Full breach record for GENWORTH NORTH AMERICA CORPORATION →Genworth North America Corporation reported a data breach affecting some of its customer information. The incident resulted from a vulnerability in Progress Software's MOVEit Transfer product, exploited by an unauthorized third party on May 29-30, 2023. Data was downloaded from the server. Genworth patched servers, investigated the impact, and is offering 24 months of credit monitoring via Kroll. The breach involves identity information such as names and potentially other PII.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_76970f80c3f978d0Oregon State AGfiled 2023-07-28(1d gap)Verified
- bd_a8ae28e31e3c4b26South Carolina State AGfiled 2023-07-28(1d gap)Verified
- bd_c5bd497e07f0a856Montana State AGfiled 2023-07-14(13d gap)Candidate
- bd_f7a5b88c1708c1daDelaware State AGfiled 2023-07-14(13d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570914
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 27, 2023
- Raw hash
- 4de760a5ffe797038063547a4a6f9d582a4b039df0fa889187afb4b9d5317431
Reporting entity
- Name
- GENWORTH NORTH AMERICA CORPORATIONnorm: genworth north america
Victim entity
- Name
- GENWORTH NORTH AMERICA CORPORATIONnorm: genworth north america
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.