HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedN-DayIDENTITY_BASICIDENTITY_GOVERNMENTCVE-2023-34362HighContained
WILTON REASSURANCE COMPANY
bd_62054ce6630d68ca · schema v1 · pii pii-v1
Full breach record for WILTON REASSURANCE COMPANY →Wilton Reassurance Company reported a data breach affecting 2,232 Maine residents, stemming from a vulnerability in the MOVEit Transfer tool used by its third-party service provider, PBI Research Services. The breach, which occurred in May 2023, resulted in the compromise of names and Social Security numbers.
Maine clockDiscovered Jun 7, 2023 → Filed with AG Aug 10, 202364d ⏱ ME AG >30d9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_be0b9ccf01ea4f7bNew Hampshire State AGCL0Pfiled 2023-08-10Verified
- bd_6dc16672758b314dCalifornia State AGfiled 2023-08-09(1d gap)Verified
- bd_61026f1556a0cbd0Montana State AGfiled 2023-08-02(8d gap)Verified
- bd_0bf216edfa80af61Oregon State AGfiled 2023-06-23(48d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 49d gap
- bd_df7b434bc84d5063Washington State AGfiled 2023-06-23(48d gap)Verified
- bd_dcc3f15736caf585California State AGfiled 2023-06-22(49d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/623f6d3b-460a-4d0b-bc26-3617f4fc2389.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 10, 2023
- Raw hash
- 23e0ad1b6133c04a2ff5c13b5d3c64ca3e42a62265ccd3ce0065ee51101d7bbb
Reporting entity
- Name
- WILTON REASSURANCE COMPANYnorm: wilton reassurance
- Industry
- Financial Services
Victim entity
- Name
- WILTON REASSURANCE COMPANYnorm: wilton reassurance
- Industry
- Financial Services
Incident
- Discovered
- Jun 7, 2023
- Materiality determined
- —
- Notification sent
- Jul 25, 2023
- Affected individuals
- 2,232
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
- CVE references
Compliance
- Time to disclose
- 9 weeks(64 days from discovery to filing)
- Compliance flags
- ME AG >30d · 64d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jun 7, 2023→ Filed with AG: Aug 10, 202364d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.