HackingVulnerability ExploitCapture Stored DataCL0PZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDownstream VictimsBusiness Associate (HIPAA)IDENTITY_BASICIDENTITY_GOVERNMENTHighResolved
TALCOTT RESOLUTION LIFE INSURANCE COMPANY
bd_7eb5a317800d59e0 · schema v1 · pii pii-v1
Full breach record for TALCOTT RESOLUTION LIFE INSURANCE COMPANY →Talcott Resolution Life Insurance Company reports a supplemental data breach involving its third-party vendor, PBI Research Services. The CL0P cybercriminal group exploited a zero-day vulnerability in MOVEit Transfer software to access and download customer data (SSN, DOB, name) on May 29-30, 2023. PBI notified 2,032 New Hampshire residents on July 19, 2023, offering credit monitoring. The incident is resolved.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_eca292e37aaf4cbbMaine State AGfiled 2023-07-25(7d gap)Verified
- bd_eced2b5c5a3a60f5Montana State AGfiled 2023-07-18(14d gap)Verified
- bd_aba190fcbb817b31Washington State AGfiled 2023-06-28(34d gap)Verified
- bd_3587cc17d4719a40California State AGfiled 2023-06-27(35d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 35d gap
- bd_9d9397e4ee227482Oregon State AGfiled 2023-06-27(35d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/talcott-resolution-life-insurance-20230801.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 1, 2023
- Raw hash
- 4292116b128af239ab8aef09c5c849f34d63c67be5f080e819664bce644f2f0f
Reporting entity
- Name
- TALCOTT RESOLUTION LIFE INSURANCE COMPANYnorm: talcott resolution life insurance
Victim entity
- Name
- TALCOTT RESOLUTION LIFE INSURANCE COMPANYnorm: talcott resolution life insurance
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Jul 19, 2023
- Affected individuals
- 2,032
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain· CL0P
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- CL0PExternalFinancial
- Regulator citations
- Talcott Resolution previously notified your office of a cybersecurity eventTalcott Resolution is providing you with an update
- Third party
- via PBI Research Services
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.