Northwestern Mutual Capital, LLC
bd_cd31c8b8a8bcd1a0 · schema v1 · pii pii-v1
Full breach record for Northwestern Mutual Capital, LLC →Northwestern Mutual reported a data breach involving its vendor Progress Software's MOVEit Transfer application. On May 31, 2023, Progress announced a previously unknown vulnerability (zero-day) in MOVEit. Unauthorized actors exploited this vulnerability to download files containing personal information of Northwestern Mutual clients. The company took the application offline, activated incident response, retained cybersecurity experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring and identity restoration services via Kroll. The incident is contained.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570701
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 22, 2023
- Raw hash
- ddace970631434948eb8b8f9ea43a493f6de10c4024d1d5d4662bedb6445dc4d
Reporting entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Victim entity
- Name
- Northwestern Mutual Capital, LLCnorm: northwestern mutual
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.