HackingVulnerability ExploitCL0PZero-DayData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)TargetedIDENTITY_BASICIDENTITY_GOVERNMENTMINORHighResolved
WILTON REASSURANCE COMPANY
bd_be0b9ccf01ea4f7b · schema v1 · pii pii-v1
Full breach record for WILTON REASSURANCE COMPANY →Wilton Reassurance Company reported a cybersecurity event involving its third-party vendor, PBI Research Services. A cybercriminal group known as CL0P exploited a zero-day vulnerability in MOVEit Transfer software between May 29-30, 2023, to exfiltrate consumer personal information. The incident affected 2,013 New Hampshire residents, whose data included names, addresses, and Social Security numbers. PBI notified affected individuals and offered credit monitoring services. The incident is considered resolved.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_62054ce6630d68caMaine State AGfiled 2023-08-10Verified
- bd_6dc16672758b314dCalifornia State AGfiled 2023-08-09(1d gap)Verified
- bd_61026f1556a0cbd0Montana State AGfiled 2023-08-02(8d gap)Verified
- bd_0bf216edfa80af61Oregon State AGfiled 2023-06-23(48d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 49d gap
- bd_df7b434bc84d5063Washington State AGfiled 2023-06-23(48d gap)Verified
- bd_dcc3f15736caf585California State AGfiled 2023-06-22(49d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/wilton-reassurance-company-20230810.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 10, 2023
- Raw hash
- 130ac2a7a432902ca4c53aa39e9766d78619815f5f19aa9394bdb16a955f56fc
Reporting entity
- Name
- WILTON REASSURANCE COMPANYnorm: wilton reassurance
Victim entity
- Name
- WILTON REASSURANCE COMPANYnorm: wilton reassurance
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jul 25, 2023
- Affected individuals
- 2,013
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTMINOR
- Attack vector
- Unauthorized Access· CL0P
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- CL0PExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General Consumer Protection Bureau
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.