AMERICAN NATIONAL GROUP INC.
bd_f92f2bd656843776 · schema v1 · pii pii-v1
Full breach record for AMERICAN NATIONAL GROUP INC. →American National Group, LLC, an insurance provider, disclosed a data security incident involving its MOVEit Transfer application. An unauthorized third party exploited a previously unknown vulnerability (CVE-2023-34362) to access systems and exfiltrate customer data, including names, SSNs, DOBs, addresses, and medical treatment information. The breach occurred on May 28, 2023. American National took the application offline, engaged third-party advisors, and notified law enforcement. Affected individuals were offered two years of complimentary credit monitoring through Experian.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_80f0bc4126269b26Delaware State AGfiled 2023-08-10Candidate
- bd_1883ffcf0cd43386California State AGfiled 2023-08-09(1d gap)Candidate
- bd_8def1b12f7e1a600Oregon State AGfiled 2023-08-09(1d gap)Verified
- bd_0a85b0d237e54f9fDelaware State AGfiled 2023-08-14(4d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/08/American-National-Sample-Notification-Letter-v2.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 10, 2023
- Raw hash
- d89c21b5f5756b2b0b465c567644e29d54396a62b5d4778de8361cd8c138b153
Reporting entity
- Name
- AMERICAN NATIONAL GROUP INC.norm: american national
Victim entity
- Name
- AMERICAN NATIONAL GROUP INC.norm: american national
Incident
- Discovered
- May 28, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notified law enforcement and are cooperating with their investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.