FEDERALItem 8.01 · voluntaryHackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_GOVERNMENTCriticalActive
GENWORTH FINANCIAL INC
bd_b9ced0a30a9484e9 · schema v1 · pii pii-v1
Full breach record for GENWORTH FINANCIAL INC →Genworth Financial, Inc. disclosed that third-party vendor PBI Research Services was subject to the MOVEit file transfer security event. As a result, the personal information of approximately 2.5-2.7 million policyholders, including Social Security numbers, was unlawfully accessed. Genworth does not use MOVEit directly. The company is investigating, notifying affected individuals and regulators, and offering credit monitoring services.
SEC clockMateriality determined Jun 22, 2023 → Filed Jun 22, 20230d ✓ SEC 4-day OK6 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2,700,000 affectedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1276520/000119312523172549/
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 22, 2023
- Raw hash
- ed02cf0f776564a0546f1c2b9b177933af8cc2582e123554318a4863e64d204b
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- GENWORTH FINANCIAL INCnorm: genworth financial
- SEC CIK
- 0001276520
- Domain
- genworth.com
Victim entity
- Name
- GENWORTH FINANCIAL INCnorm: genworth financial
- SEC CIK
- 0001276520
- Domain
- genworth.com
Incident
- Discovered
- Jun 16, 2023
- Materiality determined
- Jun 22, 2023
- Notification sent
- —
- Affected individuals
- 2,700,000
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notification to regulatory agencies as required by federal and state law
- Initial access
- supply_chain
Compliance
- Time to disclose
- 6 days(6 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jun 22, 2023→ Filed: Jun 22, 20230d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.