American National Group, LLC and its insurance subsidiaries
bd_9b1f12a9c1203e38 · schema v1 · pii pii-v1
Full breach record for American National Group, LLC and its insurance subsidiaries →2 incidents on fileAmerican National Group, LLC reported a cybersecurity event affecting its MOVEit Transfer application. An unauthorized third party, identified as the Russian criminal group CL0P, exploited a previously unknown vulnerability (zero-day) to access servers on May 28, 2023, exfiltrating customer and employee data including SSNs, DOBs, addresses, and medical treatment information. The incident was discovered on May 31, 2023, after Progress Software announced the vulnerability. 24,345 Washington residents were impacted. American National took the app offline, engaged forensic advisors, notified law enforcement, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 28, 2023
Begins
May 31, 2023
Discovered
Aug 9, 2023
Filed
vs. sector median
+1 wks slower
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.