HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
MassMutual Ascend Life Insurance Company; Annuity Investors Life Insurance Company; Manhattan National Life Insurance Company
bd_9b4ff371ed65a0f4 · schema v1 · pii pii-v1
Full breach record for MassMutual Ascend Life Insurance Company; Annuity Investors Life Insurance Company; Manhattan National Life Insurance Company →Pension Benefit Information, LLC (PBI) notified MassMutual Ascend, Annuity Investors Life, and Manhattan National Life (collectively MMA) of a MOVEit Transfer vulnerability exploited by an unauthorized third party. The incident occurred May 29-30, 2023, resulting in the exfiltration of names, SSNs, DOBs, and policy numbers. PBI patched servers, engaged Kroll for 24 months of credit monitoring, and enhanced security policies. The filing is a sample consumer notification letter submitted to the Delaware Attorney General.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/08/2023.08.17-DE-Sample-PBI-MMA-Adult-Consumer-Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 23, 2023
- Raw hash
- b9cd99fa6bff6274e30cb7ff1d4fb6dc32b019e5b033e675dd8223b3d2e61c74
Reporting entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Victim entity
- Name
- MassMutual Ascend Life Insurance Company; Annuity Investors Life Insurance Company; Manhattan National Life Insurance Companynorm: massmutual ascend life insurance company annuity investors life insurance company manhattan national life insurance
Incident
- Discovered
- May 29, 2023
- Materiality determined
- —
- Notification sent
- Aug 17, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 12 weeks(86 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.