HackingStolen CredentialsTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Massachusetts Mutual Life Insurance Company
bd_753cbcae6f5a1f01 · schema v1 · pii pii-v1
Full breach record for Massachusetts Mutual Life Insurance Company →Massachusetts Mutual Life Insurance Company notified individuals of unauthorized access to business systems via compromised agent credentials. An unknown perpetrator used social engineering to reset credentials for two agents, gaining access to client PII including names, SSNs, and account numbers. MassMutual reset credentials, notified law enforcement, and offered two years of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-101464
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 29, 2017
- Raw hash
- e7c9d02b462d5ca6b7d6395967b9231dbe9976017b453fa742052ef0f074b83b
Reporting entity
- Name
- Massachusetts Mutual Life Insurance Companynorm: massachusetts mutual life insurance
Victim entity
- Name
- Massachusetts Mutual Life Insurance Companynorm: massachusetts mutual life insurance
Incident
- Discovered
- Aug 20, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1078.004 Cloud Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the matter to Federal law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 days(9 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.