HackingVulnerability ExploitData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPIIMediumContained
LUMICO LIFE INSURANCE COMPANY
bd_d6bf8fde23a83ea1 · schema v1 · pii pii-v1
Full breach record for LUMICO LIFE INSURANCE COMPANY →Lumico Life Insurance Company disclosed a breach involving its third-party vendor, NTT Data Services, and sub-vendor Pension Benefits Information, LLC. Between May 29-30, 2023, attackers exploited a vulnerability in MOVEit Transfer software to access policyholder data. Lumico discovered the incident on June 19, 2023, and confirmed data acquisition on June 30, 2023. Affected data includes names, SSNs, dates of birth, addresses, and policy numbers. Lumico engaged Kroll for two years of credit monitoring and notified regulators and law enforcement.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_edf05202d5329622Washington State AGfiled 2023-07-27(1d gap)Verified
- bd_60ed3513a32e4a46California State AGfiled 2023-08-01(6d gap)Verified
- bd_f409b232fcffae5cDelaware State AGfiled 2023-07-16(10d gap)Candidate
- bd_a4bb1ffa233d029eOregon State AGfiled 2023-08-14(19d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/07/Lumico_Sample-Consumer-Notice-07.28.2023.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 26, 2023
- Raw hash
- 5f42d0a3e1126fe930d5e3fb903d8f8275b3197034fcf2178cd19011ebdc50ca
Reporting entity
- Name
- LUMICO LIFE INSURANCE COMPANYnorm: lumico life insurance
Victim entity
- Name
- LUMICO LIFE INSURANCE COMPANYnorm: lumico life insurance
Incident
- Discovered
- Jun 19, 2023
- Materiality determined
- —
- Notification sent
- Jul 28, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- notified relevant state regulators and federal law enforcement authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.