HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
NEW YORK LIFE INSURANCE COMPANY
bd_aea6f9438346020f · schema v1 · pii pii-v1
Full breach record for NEW YORK LIFE INSURANCE COMPANY →New York Life Insurance Company notified the California AG of a data breach affecting some customers. The incident resulted from a vulnerability in Progress Software's MOVEit Transfer, exploited by an unauthorized third party on May 29-30, 2023. Data was downloaded from the server. Affected data includes names and other elements. The company patched servers, investigated, and offered identity monitoring via Kroll.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_2275313f347a3b82Maine State AGfiled 2023-08-10Verified
- bd_0e1c9b9c854304bbMaine State AGfiled 2023-08-11(1d gap)Verified
- bd_8c7a428205597b36California State AGfiled 2023-08-11(1d gap)Verified
- bd_3e32b53431a6efdaWashington State AGfiled 2023-08-24(14d gap)Verified
Show 5 more filings ↓Show fewer ↑up to 74d gap
- bd_bd81384556d7cb8eMaine State AGfiled 2023-08-24(14d gap)Verified
- bd_fae5706e9cae755dOregon State AGfiled 2023-08-24(14d gap)Verified
- bd_166d785649d0cf77Washington State AGfiled 2023-10-23(74d gap)Candidate
- bd_8beaf5d613d1c2a9Oregon State AGfiled 2023-10-23(74d gap)Candidate
- bd_cff49122540e8170Maine State AGfiled 2023-10-23(74d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571593
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 10, 2023
- Raw hash
- ac55f179eca79b54d899fe3534a30f7a5ecd14f265bb2421c375ed7e9b912ee1
Reporting entity
- Name
- NEW YORK LIFE INSURANCE COMPANYnorm: new york life insurance
Victim entity
- Name
- NEW YORK LIFE INSURANCE COMPANYnorm: new york life insurance
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 10 weeks(71 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.