MILLIMAN, INC.
ent_019e2339b98c3e573bb44ffbcbf8d0be
Disclosures
11
State AG · 8 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
1,000,000
nationwide · State AG CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MILLIMAN, INC.
- Normalized
- milliman— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- E26C2WHERBI2OAGBGT21
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (11)newest first
- 🍁Vermont State AGas victim2024-01-12
Milliman, a professional services firm, disclosed a data breach affecting approximately 100,000 Vermont consumers. The incident resulted from a supply-chain compromise of Progress Software's MOVEit transfer application. Attackers exploited the vulnerability to exfiltrate customer data, including names, Social Security numbers, and financial account information. Milliman engaged forensic investigators and offered 24 months of credit monitoring to affected individuals.
- 🦞Maine State AGas victim2024-01-12
Milliman, Inc. reported an external system breach (hacking) occurring on May 29, 2023, discovered on May 30, 2023. The incident affected 56,457 individuals, including 224 Maine residents. Personal Identifiable Information (PII) compromised included names and Social Security Numbers. Milliman issued written notifications and provided 4 months of identity and credit monitoring through Kroll.
- 🥔Idaho State AGas reporting2023-08-18
On or around May 29-30, 2023, an unauthorized third party exploited a zero-day vulnerability (CVE-2023-34362) in Progress Software's MOVEit Transfer software, accessed by third-party vendor Pension Benefit Information, LLC (PBI). PBI stored data for client Trane Technologies. The actor downloaded personal information, including names, addresses, dates of birth, and Social Security numbers, of one Idaho resident. Trane Technologies and Milliman notified the Idaho Attorney General on August 18, 2023, and offered 24 months of credit monitoring.
- 🦞Maine State AGas victim2023-08-18
Milliman, Inc. reported an external system breach (hacking) occurring between May 29 and May 30, 2023, discovered on July 21, 2023. The incident affected 5,023 individuals, including 8 Maine residents. Personal information acquired included names and Social Security Numbers. Milliman provided 24 months of credit monitoring and identity theft protection services through Kroll.
- ⛰️New Hampshire State AGas victim2023-08-17
Milliman, Inc. notified the NH AG of a data breach involving its third-party vendor, Pension Benefit Information, LLC (PBI). PBI's MOVEit Transfer software was exploited via CVE-2023-34362 (zero-day) on May 29-30, 2023. An unauthorized actor downloaded data belonging to 335 New Hampshire residents. Milliman stopped data transfers to PBI and is enhancing vendor security. PBI patched the vulnerability and offered 24 months of credit monitoring.
- 🐻California State AGas victim2023-08-14
Milliman, Inc. reported a data breach occurring between May 29 and May 30, 2023, affecting approximately 1 million individuals. The incident involved unauthorized access to personal information including names, addresses, Social Security numbers, and financial data. The company engaged forensic investigators and is offering credit monitoring services to affected individuals.
- 🦞Maine State AGas victim2023-08-14
Milliman, Inc., a provider of administrative services for employee benefit and pension plans, reported a data breach that occurred through a third-party vendor, Pension Benefit Information, LLC (PBI). PBI utilized the MOVEit Transfer software, which contained a zero-day vulnerability (CVE-2023-34362). Between May 29 and May 30, 2023, an unauthorized third party exploited this vulnerability to access and download data from PBI's servers. The breach was discovered on July 21, 2023, and affected personal information, including names and Social Security numbers.
- 🌲Washington State AGas victim2023-08-14
Milliman, Inc., a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-05-31 and filed notice on 2023-08-14. 2,879 Washington residents were affected. 75 days elapsed between awareness and notification. 2 days to identify the breach. 0 days to contain the breach.
- 🦫Oregon State AGas victim2023-08-14
Milliman, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-14. The breach occurred during 5/29/2023 - 5/30/2023. The breach was discovered on 7/21/2023. 44,415 individuals were affected. Notice was sent on 8/14/2023.
- 🥔Idaho State AGas victim2023-08-14
Milliman, Inc. notified the Idaho Attorney General of a data breach involving its third-party vendor, Pension Benefit Information, LLC (PBI). PBI's MOVEit Transfer software was exploited via zero-day vulnerability CVE-2023-34362 between May 29-30, 2023. The incident affected 869 Idaho residents, exposing names, addresses, dates of birth, and Social Security numbers. PBI patched the vulnerability and offered 24 months of credit monitoring. Milliman halted data transfers to PBI and is reviewing vendor security practices.
- 🦬Montana State AGas victim2023-08-14
Milliman Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-08-14. The breach occurred from 5/29/2023 to 5/30/2023. 145 Montana residents were affected.
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of MILLIMAN, INC. — not by MILLIMAN, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.