HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
AMERICAN NATIONAL GROUP INC.
bd_80f0bc4126269b26 · schema v1 · pii pii-v1
Full breach record for AMERICAN NATIONAL GROUP INC. →American National Group, LLC experienced a data security incident involving the MOVEit Transfer application. An unauthorized third party exploited a vulnerability (announced by Progress Software on May 31, 2023) to access systems on May 28, 2023 and exfiltrate customer data including names, SSNs, DOBs, addresses, and medical treatment information. American National took the application offline, engaged third-party advisors, notified law enforcement, and offered two years of credit monitoring. The incident status is contained.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_f92f2bd656843776Delaware State AGfiled 2023-08-10Verified
- bd_1883ffcf0cd43386California State AGfiled 2023-08-09(1d gap)Candidate
- bd_8def1b12f7e1a600Oregon State AGfiled 2023-08-09(1d gap)Verified
- bd_0a85b0d237e54f9fDelaware State AGfiled 2023-08-14(4d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/08/American-National-Sample-Notification-Letter-v2.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 10, 2023
- Raw hash
- 915f60f75513b54f671ca5962b12aca4e0d5dc4e7f937792da2fd96b405c27fa
Reporting entity
- Name
- AMERICAN NATIONAL GROUP INC.norm: american national
Victim entity
- Name
- AMERICAN NATIONAL GROUP INC.norm: american national
Incident
- Discovered
- May 28, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notified law enforcement and are cooperating with their investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.