LUMICO LIFE INSURANCE COMPANY
ent_019e5aa1eb20065cb4304205f5264e83
Disclosures
5
State AG · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
374,675
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- LUMICO LIFE INSURANCE COMPANY
- Normalized
- lumico life insurance— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493006HNQB2CXGF1J64
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- 🦫Oregon State AGas victim2023-08-14
Lumico Life Insurance Company, Elips Life Insurance Company reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-14. The breach occurred during 5/29/2023 - 5/30/2023. The breach was discovered on 6/26/2023. 374,675 individuals were affected. Notice was sent on 7/28/2023.
- 🐻California State AGas victim2023-08-01
Lumico Life Insurance Company disclosed that a third-party service provider (NTT Data Services) and its sub-vendor (Pension Benefits Information, LLC) were compromised via an exploit of the MOVEit Transfer application vulnerability. The incident occurred between May 29-30, 2023, and was discovered on June 19, 2023. Policyholder data including names, SSNs, DOBs, and addresses was exfiltrated. Lumico engaged Kroll for identity monitoring and notified regulators.
- 🌲Washington State AGas victim2023-07-27
Lumico Life Insurance Company, Elips Life Insurance Company, a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-06-19 and filed notice on 2023-07-27. 6,209 Washington residents were affected. 38 days elapsed between awareness and notification. 21 days to identify the breach. 0 days to contain the breach.
- 💎Delaware State AGas victim2023-07-26
Lumico Life Insurance Company disclosed a breach involving its third-party vendor, NTT Data Services, and sub-vendor Pension Benefits Information, LLC. Between May 29-30, 2023, attackers exploited a vulnerability in MOVEit Transfer software to access policyholder data. Lumico discovered the incident on June 19, 2023, and confirmed data acquisition on June 30, 2023. Affected data includes names, SSNs, dates of birth, addresses, and policy numbers. Lumico engaged Kroll for two years of credit monitoring and notified regulators and law enforcement.
- 💎Delaware State AGas victim2023-07-16
Lumico Life Insurance Company notified policyholders in multiple states (including Delaware, NY, MD, DC, NC, RI, NM) of a MOVEit Transfer vulnerability exploited by cyber criminals. The breach occurred May 29-30, 2023, via third-party provider NTT Data Services and its vendor PBI. Impacted data included names, SSNs, DOBs, addresses, and policy numbers. Lumico engaged Kroll for two years of identity monitoring and notified law enforcement and state regulators. The incident is contained.