UNUM GROUP
ent_019e22787430a82186ef7901fe8222f2
Unum Group is a provider of employee benefits, including disability, life, and other insurance products, offering self-service enrollment platforms for employees.
AI-summarized from indexed web sources · Nashville, Tennessee · 2026-08-04 · source
Disclosures
24
State AG · HHS OCR · Leak Site · 9 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
650,521
nationwide · State AG IN
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- UNUM GROUP
- Normalized
- unum group— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300E32YFDO6TZ8R31
- SEC EDGAR CIK
- 0000005513
- Domain
- plane.biz
Disclosure history (24)newest first
- South Carolina State AGas victim2023-09-19
Unum Group notified South Carolina residents of a cybersecurity incident involving its MOVEit Transfer application (Progress Software). Unauthorized access occurred May 31-June 1, 2023, exploiting a vulnerability to exfiltrate data including names, SSNs, medical info, and financial data. Unum detected suspicious activity on June 1, 2023, and began notifying individuals on August 3, 2023. Response included taking the system offline, patching, and offering 24 months of credit monitoring.
- California State AGas victim2023-09-19
Unum Group notified the California Attorney General of a data breach occurring between May 31 and June 1, 2023. The incident potentially affected California residents, exposing identity information (including Social Security numbers), financial account data, health information, and employment records. Unum is offering 24 months of complimentary Experian IdentityWorks credit monitoring and identity restoration services to affected individuals. The specific cause of the breach and the number of affected individuals are not disclosed in the provided notice.
- Massachusetts State AGas victim2023-09-19
Unum Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-09-19. 320 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2023-09-05
Unum Group reported a data breach to the Oregon Attorney General. The breach was reported on 2023-09-05. The breach occurred during 5/31/2023 - 6/1/2023. The breach was discovered on 7/22/2023. Notice was sent on 8/3/2023.
- Washington State AGas victim2023-08-21
Unum Group notified Washington AG of a cybersecurity incident involving the MOVEit Transfer application. The incident exploited a zero-day vulnerability attributed to the CL0P ransomware gang. Unauthorized access occurred between May 15 and June 1, 2023. Data exfiltrated included names, SSNs, medical info, and policy data for 4,186 Washington residents. Unum engaged forensic experts, notified the FBI, and offered 24 months of credit monitoring.
- Indiana State AGas victim2023-08-03
Unum Group reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-31 and was reported on 2023-08-03. 9,667 Indiana residents were affected. 650,521 individuals affected in total.
- TENNESSEEHHS OCRas victim2023-08-03
Unum Group SACE reported to HHS on 2023-08-03 a Hacking/IT Incident affecting 559,315 individuals. Breached information located on Network Server. A software application used by a business associate exposed PHI including names, DOB, addresses, SSNs, claims, and treatment info. CE provided credit monitoring and implemented safeguards.
- Massachusetts State AGas victim2022-11-11
Unum Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-11-11. 15 Massachusetts residents were affected. The report records the breach type as paper.
- Indiana State AGas victim2022-11-10
Unum Group reported a data breach to the Indiana Attorney General. The breach occurred on 2022-08-01 and was reported on 2022-11-10. 1 Indiana residents were affected. 822 individuals affected in total.
- GLOBALLeak Siteas victim2022-02-19
- Massachusetts State AGas victim2022-01-31
Unum Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-01-31. 210 Massachusetts residents were affected. The report records the breach type as electronic.
- Delaware State AGas victim2022-01-28
Unum Group notified Delaware residents of a cybersecurity incident where an unknown actor accessed a Unum employee's email account between October 28 and November 15, 2021. Unum discovered the access on November 23, 2021. The incident involved the impermissible access of employee email, potentially exposing customer personal information. Unum secured the account, enhanced security protocols, and provided 24 months of credit monitoring via Experian.
- Indiana State AGas victim2022-01-28
Unum Group reported a data breach to the Indiana Attorney General. The breach occurred on 2021-10-28 and was reported on 2022-01-28. 114 Indiana residents were affected. 34,143 individuals affected in total.
- Oregon State AGas victim2022-01-28
Unum Group ("Unum") reported a data breach to the Oregon Attorney General. The breach was reported on 2022-01-28. The breach occurred during 10/28/2021 - 11/15/2021. The breach was discovered on 11/23/2021. 34,143 individuals were affected. Notice was sent on 1/28/2022.
- California State AGas victim2022-01-28
Unum Group experienced a cybersecurity incident where an unknown external actor accessed a Unum employee's email account between October 28, 2021, and November 15, 2021. Unum discovered the unauthorized access on November 23, 2021. The incident involved the impermissible access of customer information via compromised employee credentials. Unum secured the account, engaged cybersecurity consultants, and offered 24 months of credit monitoring to affected individuals.
- Massachusetts State AGas victim2020-10-02
Unum Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-10-02. 10 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2019-12-30
Unum Group reported a data breach to the Oregon Attorney General. The breach was reported on 2019-12-30. The breach occurred during 10/1/2019 - 10/10/2019. The breach was discovered on 10/10/2019. 8,887 individuals were affected. Notice was sent on 12/23/2019.
- Massachusetts State AGas victim2019-12-24
Unum Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-12-24. 13 Massachusetts residents were affected. The report records the breach type as electronic.
- TENNESSEEHHS OCRas victim2019-01-24
Unum Group reported to HHS on 2019-01-24 a Hacking/IT Incident affecting 532 individuals. Breached information located on Email. An employee was victim of an email phishing scheme exposing PHI including names, addresses, DOBs, SSNs, and health diagnoses. Unum retained counsel, hired forensic investigators, forced password resets, implemented MFA, and provided HIPAA training.
- Massachusetts State AGas victim2018-12-20
Unum Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-12-20. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2018-10-11
Unum Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-10-11. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2017-09-11
Unum Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-09-11. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2016-10-13
Unum Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-10-13. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2015-10-09
Unum Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-10-09. 1 Massachusetts residents were affected. The report records the breach type as electronic.
Supply-chain cascadesreviewed and confirmed
- UNUM GROUP’s filing is one of at least 97 in the Progress Software Corporation supply-chain incident (2023).
Subsidiary disclosures (6)filed by group companies
◈ These filings were made by or about subsidiaries of UNUM GROUP — not by UNUM GROUP itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Massachusetts State AGvia UNUM LIFE INSURANCE COMPANY OF AMERICA2025-04-18
Unum Life Insurance Company of reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-04-18. 45 Massachusetts residents were affected.
- GLOBALLeak Sitevia Starmount Life Insurance Company2023-10-06
starmountlife.com
- GLOBALLeak Sitevia Starmount Life Insurance Company2023-06-29
Starmount Life Insurance Company
- Massachusetts State AGvia COLONIAL LIFE & ACCIDENT INSURANCE COMPANY2022-05-24
Colonial Life & Accident Insurance Company reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-05-24. 9 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGvia COLONIAL LIFE & ACCIDENT INSURANCE COMPANY2022-05-20
Colonial Life & Accidental Insurance Company reported a data breach to the Indiana Attorney General. The breach occurred on 2022-03-22 and was reported on 2022-05-20. 19 Indiana residents were affected. 18,752 individuals affected in total.
- LOUISIANAHHS OCRvia Starmount Life Insurance Company2019-12-09
Starmount Life Insurance Company (LA), a Health Plan, reported to HHS on 2019-12-09 a Hacking/IT Incident affecting 630 individuals. Several employees were victims of an email phishing scheme, compromising ePHI including names, dates of birth, Social Security numbers, financial information, and member identification numbers. Breached information located in Email. The CE notified HHS, affected individuals, and the media, and implemented additional administrative and technical safeguards. OCR obtained assurances of corrective action.