HackingVulnerability ExploitZero-DayData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTCVE-2023-34362MediumContained
MILLIMAN, INC.
bd_d1cb5766b2805d52 · schema v1 · pii pii-v1
Full breach record for MILLIMAN, INC. →Milliman, Inc. notified the Idaho Attorney General of a data breach involving its third-party vendor, Pension Benefit Information, LLC (PBI). PBI's MOVEit Transfer software was exploited via zero-day vulnerability CVE-2023-34362 between May 29-30, 2023. The incident affected 869 Idaho residents, exposing names, addresses, dates of birth, and Social Security numbers. PBI patched the vulnerability and offered 24 months of credit monitoring. Milliman halted data transfers to PBI and is reviewing vendor security practices.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_5fb2b809a54c9f68California State AGfiled 2023-08-14Verified
- bd_847189c2c427ed3bMaine State AGfiled 2023-08-14Candidate
- bd_b71e461fa51aa4b2Washington State AGfiled 2023-08-14Verified
- bd_c290a9c83b4262b5Oregon State AGfiled 2023-08-14Verified
Show 3 more filings ↓Show fewer ↑up to 4d gap
- bd_efdfa8d0534820d3Montana State AGfiled 2023-08-14Verified
- bd_0784ee17d069ca5fNew Hampshire State AGfiled 2023-08-17(3d gap)Verified
- bd_ef7ad7a4aedf79b1Maine State AGfiled 2023-08-18(4d gap)Verified
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2023/08/8-14-2023-Milliman-Inc.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 14, 2023
- Raw hash
- 229afaa8d4867a51785bdf5de94a3057d6f17dc7952725b15adbefb554503a96
Reporting entity
- Name
- MILLIMAN, INC.norm: milliman
Victim entity
- Name
- MILLIMAN, INC.norm: milliman
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Aug 14, 2023
- Affected individuals
- 869
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Submitted notice to Idaho Attorney General’s Office, Consumer Protection Division
- Initial access
- exploit_public_facing
- CVE references
Compliance
- Time to disclose
- 11 weeks(75 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.