HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Global Atlantic
bd_996dba95423b3558 · schema v1 · pii pii-v1
Full breach record for Global Atlantic →The Global Atlantic Financial Group LLC (GAFG) disclosed a cybersecurity incident involving its third-party vendor, Pension Benefits Information LLC (PBI). PBI's MOVEit file transfer application was exploited via an unpatched vulnerability (zero-day at the time) between May 29-30, 2023. Cybercriminals exfiltrated policyholder data, including names and government identifiers (SSNs, DOBs). GAFG notified affected individuals in July 2023, offering two years of credit monitoring. GAFG stated its own environment was not directly compromised.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_2fd32b32e3e18818California State AGfiled 2023-08-14(17d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/08/Sample-GAFG-Policyholder-Notification-Template-Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 28, 2023
- Raw hash
- 8882f3b749588b1dd080991e3f0ab0592ab6f1882136d8d16c9872870193afe4
Reporting entity
- Name
- Global Atlanticnorm: global atlantic
- Domain
- globalatlantic.com
Victim entity
- Name
- Global Atlanticnorm: global atlantic
- Domain
- globalatlantic.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Jul 28, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the incident to the appropriate authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.