HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
THE PRUDENTIAL INSURANCE COMPANY OF AMERICA
bd_dbaeb4759ee6cddb · schema v1 · pii pii-v1
Full breach record for THE PRUDENTIAL INSURANCE COMPANY OF AMERICA →The Prudential Insurance Company of America reported a data breach affecting some of its customers' information held by third-party vendor Pension Benefit Information, LLC (PBI). An unauthorized third party exploited a vulnerability in PBI's MOVEit Transfer software, accessing servers on May 29-30, 2023, and downloading data. Affected data included names, addresses, dates of birth, phone numbers, and Social Security numbers. PBI patched servers, notified law enforcement, and offered 24 months of credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_3b84a61cb6735164Oregon State AGfiled 2023-07-31Verified
- bd_7e688073d09fd315Maine State AGfiled 2023-07-31Verified
- bd_0b4a2cab983724faWashington State AGfiled 2023-07-27(4d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571119
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 31, 2023
- Raw hash
- 54c81966228b01e197c1cb587e39f08c31d6ecf009f7fc3e169a0f017e0794a2
Reporting entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Victim entity
- Name
- THE PRUDENTIAL INSURANCE COMPANY OF AMERICAnorm: the prudential insurance company of america
- Domain
- prudential.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 ChannelT1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Pension Benefit Information, LLC
- Initial access
- supply_chain
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.