UNUM GROUP
ent_019e22787430a82186ef7901fe8222f2
Disclosures
10
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
559,315
nationwide · HHS OCR TN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- UNUM GROUP
- Normalized
- unum group— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300E32YFDO6TZ8R31
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- 🐻California State AGas victim2023-09-19
Unum Group notified the California Attorney General of a data breach occurring between May 31 and June 1, 2023. The incident potentially affected California residents, exposing identity information (including Social Security numbers), financial account data, health information, and employment records. Unum is offering 24 months of complimentary Experian IdentityWorks credit monitoring and identity restoration services to affected individuals. The specific cause of the breach and the number of affected individuals are not disclosed in the provided notice.
- 🦫Oregon State AGas victim2023-09-05
Unum Group reported a data breach to the Oregon Attorney General. The breach was reported on 2023-09-05. The breach occurred during 5/31/2023 - 6/1/2023. The breach was discovered on 7/22/2023. Notice was sent on 8/3/2023.
- 🌲Washington State AGas victim2023-08-21
Unum Group, a finance sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-06-04 and filed notice on 2023-08-21. 4,186 Washington residents were affected. 78 days elapsed between awareness and notification. 4 days to identify the breach. 0 days to contain the breach.
- TNHHS OCRas victim2023-08-03
Unum Group SACE reported to HHS on 2023-08-03 a Hacking/IT Incident affecting 559,315 individuals. Breached information located on Network Server. A software application used by a business associate exposed PHI including names, DOB, addresses, SSNs, claims, and treatment info. CE provided credit monitoring and implemented safeguards.
- 🌲Washington State AGas victim2022-01-31
Unum Group ("Unum"), a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2021-11-23 and filed notice on 2022-01-31. 1,610 Washington residents were affected. 69 days elapsed between awareness and notification. 26 days to identify the breach. 0 days to contain the breach.
- 💎Delaware State AGas victim2022-01-28
Unum Group notified Delaware residents of a cybersecurity incident where an unknown actor accessed an employee's email account between Oct 28 and Nov 15, 2021. Unum discovered the breach on Nov 23, 2021. The incident involved unauthorized access to email credentials, potentially exposing customer PII. Unum secured the account, enhanced email security, and offered 24 months of credit monitoring via Experian.
- 🦫Oregon State AGas victim2022-01-28
Unum Group ("Unum") reported a data breach to the Oregon Attorney General. The breach was reported on 2022-01-28. The breach occurred during 10/28/2021 - 11/15/2021. The breach was discovered on 11/23/2021. 34,143 individuals were affected. Notice was sent on 1/28/2022.
- 🐻California State AGas victim2022-01-28
Unum Group experienced a cybersecurity incident where an unknown actor accessed a Unum employee's email account between October 28, 2021, and November 15, 2021. The breach involved unauthorized access to email contents, potentially exposing customer PII. Unum secured the account, enhanced email security protocols, and provided 24 months of complimentary credit monitoring via Experian to affected individuals.
- 🦫Oregon State AGas victim2019-12-30
Unum Group reported a data breach to the Oregon Attorney General. The breach was reported on 2019-12-30. The breach occurred during 10/1/2019 - 10/10/2019. The breach was discovered on 10/10/2019. 8,887 individuals were affected. Notice was sent on 12/23/2019.
- 💎Delaware State AGas victim2014-01-10
Unum Group notified Delaware residents of a cybersecurity incident where an unknown actor accessed a Unum employee's email account between October 28 and November 15, 2021. Unum discovered the access on November 23, 2021. The incident involved the impermissible access of employee email, potentially exposing customer personal information. Unum secured the account, enhanced security protocols, and provided 24 months of credit monitoring via Experian.
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of UNUM GROUP — not by UNUM GROUP itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.