HackingVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)PIIIDENTITY_BASICMediumContained
Pension Benefit Information, LLC
bd_88a232a96ae8d0e9 · schema v1 · pii pii-v1
Full breach record for Pension Benefit Information, LLC →PBI Research Services (PBI) disclosed that an unauthorized third party exploited a vulnerability in MOVEit Transfer software to access files on May 29-30, 2023. The incident affected 1,318 New Hampshire residents, whose PII was downloaded. PBI patched the software, notified law enforcement, and offered one year of credit monitoring.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_31eb3a86b455ca2aCalifornia State AGfiled 2023-08-24Verified
- bd_f52c76855c9e670bNew Hampshire State AGfiled 2023-08-24Verified
- bd_ed5751101a0d93eeVermont State AGfiled 2023-08-25(1d gap)Verified
- bd_5a81a9b3803e493cDelaware State AGfiled 2023-08-23(1d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 41d gap
- bd_bc42d7fee9bd036cMaine State AGfiled 2023-08-16(8d gap)Candidate
- bd_8a9b6ba4c65dda36Delaware State AGfiled 2023-07-28(27d gap)Candidate
- bd_eb47f1a922c8d8ddDelaware State AGfiled 2023-07-17(38d gap)Candidate
- bd_729ad9694adf695eNew Hampshire State AGfiled 2023-07-14(41d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/pbi-research-services-20230824.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 24, 2023
- Raw hash
- 6f613f1a6f6958dae8be1c37da6732304cf6ecc861a139eb38ab4a5b57c10a5e
Reporting entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Victim entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 1,318
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(85 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.