HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTCriticalContained
FIDELITY & GUARANTY LIFE INSURANCE COMPANY
bd_92cedaacf40b2902 · schema v1 · pii pii-v1
Full breach record for FIDELITY & GUARANTY LIFE INSURANCE COMPANY →Fidelity & Guaranty Life Insurance Company notified the Idaho Attorney General of a cybersecurity incident involving its third-party vendor, PBI Research Services. PBI's MOVEit Secure Transfer application was exploited, leading to the exfiltration of policyholder data (names, SSNs, DOBs, contact info) for approximately 873,000 individuals across 50 states, including 3,158 in Idaho. F&G offered 12 months of credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_95a07b61fb5e43d3Montana State AGfiled 2023-07-28Verified
- bd_b4ad819409c0eec1Delaware State AGfiled 2023-08-01(4d gap)Verified
- bd_5465b86396891a46Maine State AGfiled 2023-07-20(8d gap)Candidate
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2023/07/7-28-2023-Fidelity-Guaranty-Life-Insurance-Company.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 28, 2023
- Raw hash
- b825b7e44856954aabc13e272cb66dbbbe315cedebe2b8f3b6a2fef9dfc0d32f
Reporting entity
- Name
- FIDELITY & GUARANTY LIFE INSURANCE COMPANYnorm: fidelity guaranty life insurance
- Domain
- fglife.com
Victim entity
- Name
- FIDELITY & GUARANTY LIFE INSURANCE COMPANYnorm: fidelity guaranty life insurance
- Domain
- fglife.com
Incident
- Discovered
- Jun 6, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 873,000
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Idaho Attorney General's Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.