HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
WILTON REASSURANCE COMPANY
bd_6dc16672758b314d · schema v1 · pii pii-v1
Full breach record for WILTON REASSURANCE COMPANY →Wilton Reassurance Company notified the California AG of a data breach affecting its customers. An unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer software, accessing PBI's servers on May 29-30, 2023, and downloading data. PBI discovered the vulnerability on May 31, 2023. Affected data includes identity information. PBI patched servers, investigated, and offered 12 months of credit monitoring via Kroll.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_62054ce6630d68caMaine State AGfiled 2023-08-10(1d gap)Verified
- bd_be0b9ccf01ea4f7bNew Hampshire State AGCL0Pfiled 2023-08-10(1d gap)Verified
- bd_61026f1556a0cbd0Montana State AGfiled 2023-08-02(7d gap)Verified
- bd_0bf216edfa80af61Oregon State AGfiled 2023-06-23(47d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 48d gap
- bd_df7b434bc84d5063Washington State AGfiled 2023-06-23(47d gap)Verified
- bd_dcc3f15736caf585California State AGfiled 2023-06-22(48d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571551
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 9, 2023
- Raw hash
- 2725dca36d774c93e6d0f7961d22b38bde9162f69dc9a117cb5a2f509f463c1b
Reporting entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Victim entity
- Name
- WILTON REASSURANCE COMPANYnorm: wilton reassurance
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 10 weeks(70 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.