UNUM GROUP
bd_e9863c8671e00ee8 · schema v1 · pii pii-v1
Full breach record for UNUM GROUP →12 incidents on fileUnum Group notified Washington AG of a cybersecurity incident involving the MOVEit Transfer application. The incident exploited a zero-day vulnerability attributed to the CL0P ransomware gang. Unauthorized access occurred between May 15 and June 1, 2023. Data exfiltrated included names, SSNs, medical info, and policy data for 4,186 Washington residents. Unum engaged forensic experts, notified the FBI, and offered 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 15, 2023
Begins
Jun 1, 2023
Discovered
Aug 21, 2023
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Oregon State AGbd_be1b59e27105faaa2023-09-05 · +15dVerified
- Indiana State AGbd_7e4b64e3b2796a5e2023-08-03 · +18dCandidate
- HHS OCRbd_daff25a5bf2dc4eb2023-08-03 · +18dCandidate
- South Carolina State AGbd_5fd3c14b044d2a092023-09-19 · +29dVerified
Show 2 more filings ↓Show fewer ↑up to 29d gap
- California State AGbd_60e06d7b099885312023-09-19 · +29dVerified
- Massachusetts State AGbd_d63872c90f649d742023-09-19 · +29dVerified
Filing propagation · 7 filings · 7 states
View merged incident ↗Pattern: first filing Aug 3 (IN), last Sep 19 (MA) — a 47-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.