HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CONTINENTAL GENERAL INSURANCE COMPANY
bd_68b8b3434bda38e6 · schema v1 · pii pii-v1
Full breach record for CONTINENTAL GENERAL INSURANCE COMPANY →Pension Benefit Information, LLC (PBI) notified consumers that an unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer software, accessing PBI's servers on May 29-30, 2023. The actor downloaded data including names, SSNs, dates of birth, gender, zip codes, and policy numbers. PBI patched servers, investigated the scope, and is offering 24 months of credit monitoring via Kroll.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_52d7dbae9a98c6eeOregon State AGfiled 2023-08-24Verified
- bd_a938df8e8b0e37c0Maine State AGfiled 2023-08-24Verified
- bd_020ad4b72d6c73c8Montana State AGfiled 2023-08-21(3d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572319
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 24, 2023
- Raw hash
- a045f54af0b2d8ca71c4e19d2851210767e3c327fc82060caf67eecace73f117
Reporting entity
- Name
- CONTINENTAL GENERAL INSURANCE COMPANYnorm: continental general insurance
Victim entity
- Name
- CONTINENTAL GENERAL INSURANCE COMPANYnorm: continental general insurance
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 12 weeks(85 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.