HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICMediumContained
Pension Benefit Information, LLC
bd_f52c76855c9e670b · schema v1 · pii pii-v1
Full breach record for Pension Benefit Information, LLC →Pension Benefit Information, LLC (PBI) disclosed a data breach involving its MOVEit Transfer server exploited by an unauthorized third party on May 29-30, 2023. The incident affected 1,058 New Hampshire residents affiliated with PBI's clients. PBI patched servers, engaged in investigation, and provided 24 months of credit monitoring services to affected individuals.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_31eb3a86b455ca2aCalifornia State AGfiled 2023-08-24Verified
- bd_88a232a96ae8d0e9New Hampshire State AGfiled 2023-08-24Verified
- bd_ed5751101a0d93eeVermont State AGfiled 2023-08-25(1d gap)Verified
- bd_5a81a9b3803e493cDelaware State AGfiled 2023-08-23(1d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 41d gap
- bd_bc42d7fee9bd036cMaine State AGfiled 2023-08-16(8d gap)Candidate
- bd_8a9b6ba4c65dda36Delaware State AGfiled 2023-07-28(27d gap)Candidate
- bd_eb47f1a922c8d8ddDelaware State AGfiled 2023-07-17(38d gap)Candidate
- bd_729ad9694adf695eNew Hampshire State AGfiled 2023-07-14(41d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/pension-benefit-information-20230824.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 24, 2023
- Raw hash
- 143571f6b00330d041f37c5e4e9c45f09426994a3db31aaaabd9aa83e6bc972d
Reporting entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Victim entity
- Name
- Pension Benefit Information, LLCnorm: pension benefit information
- Domain
- mypensionbenefitinformation.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Aug 25, 2023
- Affected individuals
- 1,058
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Provided notice to ClientProviding written notice of this event to appropriate governmental regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(85 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.