MalwareRansomwareData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Massachusetts Mutual Life Insurance Company
bd_d918850cbbde809b · schema v1 · pii pii-v1
Full breach record for Massachusetts Mutual Life Insurance Company →Massachusetts Mutual Life Insurance Company reported a ransomware incident involving third-party provider Infosys McCamish Systems (IMS) on November 2, 2023. The breach affected 39 Idaho residents, exposing names, Social Security numbers, dates of birth, and addresses. IMS engaged Unit 42 and EY for investigation and remediation. No evidence of data misuse was found, but 24 months of Experian IdentityForce was offered to affected individuals.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_ac0b6dc3df0c296eIndiana State AGfiled 2024-03-21Candidate
- bd_de5ae1ceb3f549eeCalifornia State AGfiled 2024-03-21Verified
- bd_bdbff42b2e4ac737Indiana State AGfiled 2024-04-26(36d gap)Candidate
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2024/03/3-21-2024-Massachusetts-Mutual-Life-Insurance-Company.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 21, 2024
- Raw hash
- fbc0bbaaf8258a84c756b682e2249af7ba5a5bb25f4eed97a38e5e4486386a44
Reporting entity
- Name
- Massachusetts Mutual Life Insurance Companynorm: massachusetts mutual life insurance
Victim entity
- Name
- Massachusetts Mutual Life Insurance Companynorm: massachusetts mutual life insurance
Incident
- Discovered
- Nov 2, 2023
- Materiality determined
- Feb 5, 2024
- Notification sent
- Mar 21, 2024
- Affected individuals
- 39
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Idaho Attorney General's Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 20 weeks(140 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.