HackingVulnerability ExploitData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
LUMICO LIFE INSURANCE COMPANY
bd_f409b232fcffae5c · schema v1 · pii pii-v1
Full breach record for LUMICO LIFE INSURANCE COMPANY →Lumico Life Insurance Company notified policyholders in multiple states (including Delaware, NY, MD, DC, NC, RI, NM) of a MOVEit Transfer vulnerability exploited by cyber criminals. The breach occurred May 29-30, 2023, via third-party provider NTT Data Services and its vendor PBI. Impacted data included names, SSNs, DOBs, addresses, and policy numbers. Lumico engaged Kroll for two years of identity monitoring and notified law enforcement and state regulators. The incident is contained.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_d6bf8fde23a83ea1Delaware State AGfiled 2023-07-26(10d gap)Verified
- bd_edf05202d5329622Washington State AGfiled 2023-07-27(11d gap)Verified
- bd_60ed3513a32e4a46California State AGfiled 2023-08-01(16d gap)Verified
- bd_a4bb1ffa233d029eOregon State AGfiled 2023-08-14(29d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/07/Lumico_Sample-Consumer-Notice-07.28.2023.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 16, 2023
- Raw hash
- 937718b74fe6ec0f8e58414e26cb8d6eb64131cf82dea5d9f660c12317acafd7
Reporting entity
- Name
- LUMICO LIFE INSURANCE COMPANYnorm: lumico life insurance
- Domain
- lumico.com
Victim entity
- Name
- LUMICO LIFE INSURANCE COMPANYnorm: lumico life insurance
- Domain
- lumico.com
Incident
- Discovered
- Jun 19, 2023
- Materiality determined
- —
- Notification sent
- Jul 28, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified relevant state regulators and federal law enforcement authorities
- Third party
- via NTT Data Services
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.