HackingVulnerability ExploitSupply Chain (3P Vendor)Zero-DayData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTCVE-2023-34362MediumContained
MILLIMAN, INC.
bd_847189c2c427ed3b · schema v1 · pii pii-v1
Full breach record for MILLIMAN, INC. →Milliman, Inc., a provider of administrative services for employee benefit and pension plans, reported a data breach that occurred through a third-party vendor, Pension Benefit Information, LLC (PBI). PBI utilized the MOVEit Transfer software, which contained a zero-day vulnerability (CVE-2023-34362). Between May 29 and May 30, 2023, an unauthorized third party exploited this vulnerability to access and download data from PBI's servers. The breach was discovered on July 21, 2023, and affected personal information, including names and Social Security numbers.
Maine clockDiscovered Jul 21, 2023 → Filed with AG Aug 14, 202324d ✓ ME AG ≤30d24 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_5fb2b809a54c9f68California State AGfiled 2023-08-14Verified
- bd_b71e461fa51aa4b2Washington State AGfiled 2023-08-14Verified
- bd_c290a9c83b4262b5Oregon State AGfiled 2023-08-14Verified
- bd_d1cb5766b2805d52Idaho State AGfiled 2023-08-14Verified
Show 3 more filings ↓Show fewer ↑up to 4d gap
- bd_efdfa8d0534820d3Montana State AGfiled 2023-08-14Verified
- bd_0784ee17d069ca5fNew Hampshire State AGfiled 2023-08-17(3d gap)Verified
- bd_ef7ad7a4aedf79b1Maine State AGfiled 2023-08-18(4d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/903ecb46-93b2-4986-aae5-ec7e088625f8.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 14, 2023
- Raw hash
- d9132117a95a70661e963ac449a262ba68725b70c3f357c31e81593bf01d53a8
Reporting entity
- Name
- MILLIMAN, INC.norm: milliman
Victim entity
- Name
- MILLIMAN, INC.norm: milliman
Incident
- Discovered
- Jul 21, 2023
- Materiality determined
- —
- Notification sent
- Aug 14, 2023
- Affected individuals
- 160
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- Threat actor
- External
- CVE references
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 24d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jul 21, 2023→ Filed with AG: Aug 14, 202324d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.