HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
PRUDENTIAL INSURANCE COMPANY OF AMERICA
bd_f5ee337a95f0f543 · schema v1 · pii pii-v1
Full breach record for PRUDENTIAL INSURANCE COMPANY OF AMERICA →Prudential Insurance Company of America notified Delaware AG of a cybersecurity incident detected on February 5, 2024. An unauthorized third party accessed company systems on February 4, 2024, and exfiltrated a small percentage of personal information, including names, addresses, and government identifiers. Prudential engaged external experts, notified law enforcement, and provided 24 months of complimentary credit monitoring. The incident is contained, and no fraud is currently known.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_36841bd9613d029dCalifornia State AGfiled 2024-03-29Verified
- bd_eb8d330c9dcc702bMaine State AGfiled 2024-03-29Candidate
- bd_b3527d1aa38e9c73Maine State AGfiled 2024-04-01(3d gap)Verified
- bd_63338cbe564e2833Washington State AGfiled 2024-04-23(25d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 56d gap
- bd_1b617c45cf572f7aOregon State AGfiled 2024-05-24(56d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/05/Prudential-Insurance-Company-of-America-Individual-Notification-Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 29, 2024
- Raw hash
- 45fe54d8987ab209b57a8bce1ca49788a973bcbd52c2906d2f7ded3d12717980
Reporting entity
- Name
- PRUDENTIAL INSURANCE COMPANY OF AMERICAnorm: prudential insurance company of america
Victim entity
- Name
- PRUDENTIAL INSURANCE COMPANY OF AMERICAnorm: prudential insurance company of america
Incident
- Discovered
- Feb 5, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- reported this matter to relevant law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.