COREBRIDGE FINANCIAL, INC.
ent_019de5f6054912168c9e07a41d86dea5
Disclosures
6
State AG · SEC 8-K · 6 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
101,027
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- COREBRIDGE FINANCIAL, INC.
- Normalized
- corebridge financial— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300XY1661QCIA7J65
- SEC EDGAR CIK
- 0001889539
- Domain
- corebridgefinancial.com
Disclosure history (6)newest first
- 🏎️Indiana State AGas victim2024-02-13
Corebridge Financial, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-01-27 and was reported on 2024-02-13. 2 Indiana residents were affected.
- 🐻California State AGas victim2023-07-27
Corebridge Financial, Inc. reported a data breach affecting its customers via third-party vendor Pension Benefit Information, LLC (PBI). An unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer to access PBI servers on May 29-30, 2023, and exfiltrated data. Affected data includes names, Social Security numbers, policy/account numbers, dates of birth, and addresses. Corebridge's own systems were not impacted. PBI notified law enforcement, patched servers, and offered 24 months of credit monitoring.
- 🦫Oregon State AGas victim2023-07-27
Corebridge Financial, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-07-27. The breach occurred during 1/1/0001.
- 🦬Montana State AGas victim2023-07-27
Corebridge Financial, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-07-27. The breach occurred from 5/29/2023 to 5/30/2023. 15,080 Montana residents were affected.
- 🌲Washington State AGas victim2023-07-25
Corebridge Financial, Inc., a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-06-02 and filed notice on 2023-07-25. 101,027 Washington residents were affected. 53 days elapsed between awareness and notification. 4 days to identify the breach. 0 days to contain the breach.
- FEDERALSEC 8-Kas victim2023-06-26
Corebridge Financial, Inc. disclosed a security incident involving a third-party vendor's MOVEit Transfer instance. The vendor exploited a zero-day vulnerability, compromising customer data including Social Security numbers and policy numbers. Corebridge launched an investigation, notified regulators, and offered credit monitoring services. The incident did not impact Corebridge's own systems.
Subsidiary disclosures (7)filed by group companies
◈ These filings were made by or about subsidiaries of COREBRIDGE FINANCIAL, INC. — not by COREBRIDGE FINANCIAL, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🏎️Indiana State AGvia The Variable Annuity Life Insurance Company2025-10-30
The Variable Annuity Life Insurance Company reported a data breach to the Indiana Attorney General. The breach occurred on 2025-05-04 and was reported on 2025-10-30. 1 Indiana residents were affected.
- 🏎️Indiana State AGvia The Variable Annuity Life Insurance Company2024-03-08
The Variable Annuity Life Insurance Company reported a data breach to the Indiana Attorney General. The breach occurred on 2023-09-24 and was reported on 2024-03-08. 1 Indiana residents were affected. 62 individuals affected in total.
- 🏎️Indiana State AGvia The Variable Annuity Life Insurance Company2024-03-08
The Variable Annuity Life Insurance Company reported a data breach to the Indiana Attorney General. The breach occurred on 2024-02-20 and was reported on 2024-03-08. 1 Indiana residents were affected.
- ⛰️New Hampshire State AGvia VALIC Retirement Services Company2023-07-31
State AG filing for VALIC Retirement Services Company in New Hampshire. The attachment content is empty; no breach details, dates, or data types were extracted from the provided source.
- 🦞Maine State AGvia VALIC Retirement Services Company2023-07-31
VALIC Retirement Services Company (VRSCO) reported a data breach affecting 2,722 Maine residents. The breach was attributed to an incident at a third-party service provider that occurred between May 29, 2023, and May 30, 2023. The company discovered the breach on June 26, 2023. The compromised information includes names and Social Security numbers. VRSCO began notifying affected individuals on July 27, 2023, and offered 24 months of complimentary credit monitoring, fraud consultation, and identity restoration services through Kroll.
- 🌺Hawaii State AGvia The Variable Annuity Life Insurance Company2014-02-27
AIG Life and Retirement, The Variable Annuity Life Insurance Co. reported a data breach to the Hawaii Office of Consumer Protection. The office was notified on 2014/02.27. Breach type: Data Theft by Employee or Contractor. 4,015 Hawaii residents were affected. Recovered from the Internet Archive after the notice was removed from the OCP table.
- 🐻California State AGvia The Variable Annuity Life Insurance Company2014-02-26
The Variable Annuity Life Insurance Company reported a data security breach to the California Attorney General. The breach occurred on October 25, 2007. The provided source document contains only the filing metadata and an empty attachment placeholder; no narrative details regarding the nature of the breach, data types affected, or number of individuals impacted are available in the text.