Social EngineeringVishingTargetedCustomer Data InvolvedPIIIDENTITY_BASICLowActive
CNO Financial Group
bd_cf4aa13c35b5ab61 · schema v1 · pii pii-v1
Full breach record for CNO Financial Group →CNO Services, LLC reported a vishing incident to the New Hampshire Attorney General on June 8, 2026. On May 15, 2026, CNO became aware of fraudulent calls impersonating its IT Service Desk. A scammer successfully gained limited, unauthorized access to one associate's account. The incident involved a small number of associates, and no customer information was accessed. CNO engaged forensic investigators and law enforcement, changed helpdesk procedures, and is offering complimentary identity protection services to affected individuals. The investigation is ongoing.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_35331b950f52b307Maine State AGfiled 2026-06-08Verified
- bd_8ea207987f1521acTexas State AGfiled 2026-06-09(1d gap)Verified
- bd_a08bd193f520e463Massachusetts State AGfiled 2026-06-01(7d gap)Candidate
- bd_40c071a3ad048005Texas State AGfiled 2026-07-03(25d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/cno-services-20260608.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 8, 2026
- Raw hash
- 6ff7aca0800a0728007d6c74456d6a95fe222018bee7647c0d39ee1187bfb655
Reporting entity
- Name
- CNO Financial Groupnorm: cno financial
- Domain
- cnoinc.com
Victim entity
- Name
- CNO Financial Groupnorm: cno financial
- Domain
- cnoinc.com
Incident
- Discovered
- May 15, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported this incident to law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.