CNO FINANCIAL GROUP, INC.
ent_11e0fca1996a40d30c1ed52d
Disclosures
11
State AG · 7 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
11,786
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CNO FINANCIAL GROUP, INC.
- Normalized
- cno financial— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 11XPYHB76MPM4Y4P2897
- SEC EDGAR CIK
- 0001224608
- Domain
- cnoinc.com
Disclosure history (11)newest first
- New Hampshire State AGas reporting2026-07-13
CNO Services, LLC reported a security breach involving vishing (voice phishing) targeting associates. On May 15, 2026, the company became aware of fraudulent IT Service Desk calls. In one instance, a scammer gained limited unauthorized access to historical employment-related data. The incident affected 34 New Hampshire residents, whose names, Social Security numbers, and dates of birth may have been involved. Individuals were notified on June 12, 2026. The company engaged forensic investigators, reported to law enforcement, and is enhancing internal security controls and helpdesk procedures.
- Texas State AGas reporting2026-07-03
CNO Services, LLC based in Carmel, Indiana, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-05-15 and reported on 2026-07-03. 530 Texas residents were affected. 11,786 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Date of Birth. Consumers were notified via U.S. Mail.
- Nebraska State AGas reporting2026-06-12
CNO Services LLC reports a supplemental vishing incident discovered on May 15, 2026, where a scammer impersonated IT support to gain limited unauthorized access to one associate's employment data. The company engaged forensic investigators and federal law enforcement, changed helpdesk procedures, and provided complimentary identity protection services via IDX to affected associates.
- Texas State AGas reporting2026-06-09
CNO Services, LLC based in Carmel, Indiana, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-05-15 and reported on 2026-06-09. 10 Texas residents were affected. Types of information involved: Name of individual;Social Security Number Information;Date of Birth.
- Maine State AGas reporting2026-06-08
CNO Services, LLC reported a data breach affecting 10 Maine residents. The breach occurred and was discovered on May 15, 2026. The company provided written notification on June 12, 2026, and offered 12 months of identity theft protection services through IDX, including credit monitoring and insurance.
- Massachusetts State AGas reporting2026-06-08
CNO Services, LLC issued a supplemental breach notification in Massachusetts regarding an incident targeting the company's internal information. While the primary target was corporate data, a limited amount of employee personal information was involved. CNO engaged IDX to provide 18 months of complimentary identity protection, credit monitoring, and ID theft recovery services to affected associates.
- New Hampshire State AGas reporting2026-06-08
CNO Services, LLC reported a vishing incident to the New Hampshire Attorney General on June 8, 2026. On May 15, 2026, CNO became aware of fraudulent calls impersonating its IT Service Desk. A scammer successfully gained limited, unauthorized access to one associate's account. The incident involved a small number of associates, and no customer information was accessed. CNO engaged forensic investigators and law enforcement, changed helpdesk procedures, and is offering complimentary identity protection services to affected individuals. The investigation is ongoing.
- Illinois State AGas reporting2026-06-01
CNO SERVICES, LLC filed a data-breach notice with the Illinois Attorney General in June 2026 (case 26-06-1252). The register records the breach as discovered on May 15, 2026. Personal information types reported: drivers license, username password. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Indiana State AGas victim2021-07-21
CNO Financial Group, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-12-01 and was reported on 2021-07-21. 21 Indiana residents were affected. 562 individuals affected in total.
- New Hampshire State AGas victim2021-07-21
CNO Financial Group, Inc. notified the New Hampshire Attorney General of a cybersecurity incident involving its vendor, Guidehouse. An unauthorized third party accessed an unencrypted file shared via the Accellion File Transfer Appliance (FTA) between December 2020 and January 2021. The incident affected 3 New Hampshire residents, exposing names, dates of birth, policy numbers, Social Security numbers, and addresses. CNO stated no systems were compromised directly, but offered two years of credit monitoring to affected individuals.
- Maine State AGas victim2021-07-20
CNO Financial Group, Inc. experienced an external system breach between December 1, 2020, and January 20, 2021. The breach, discovered on May 25, 2021, affected 562 individuals. The compromised information included names and Social Security numbers. The company offered 24 months of identity theft protection services through Experian to affected individuals.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of CNO FINANCIAL GROUP, INC. — not by CNO FINANCIAL GROUP, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- South Carolina State AGvia Bankers Life and Casualty Company2024-02-12
Bankers Life and Casualty Company notified South Carolina residents of a SIM swapping attack targeting a senior officer's cellular account on November 29, 2023. The attacker bypassed MFA to access company data, potentially exposing names, SSNs, DOBs, and policy numbers. The company disabled access, reset passwords, engaged the FBI and forensic investigators, and offered credit monitoring.
- Montana State AGvia WASHINGTON NATIONAL INSURANCE COMPANY2024-01-31
Washington National Insurance Company notified Montana residents of a SIM swapping attack targeting a senior officer's cellular account on November 29, 2023. The threat actor bypassed MFA and accessed personal information including names, SSNs, dates of birth, and policy numbers. The company disabled access, reset passwords, engaged the FBI and forensic investigators, and offered IDX identity protection services.
- New Hampshire State AGvia WASHINGTON NATIONAL INSURANCE COMPANY2024-01-31
Washington National Insurance Company disclosed a data breach affecting 4 New Hampshire residents. On November 29, 2023, the company discovered that a threat actor identified as 'Scattered Spider' conducted a SIM-swapping attack on a senior officer's Verizon cellular account. This allowed the actor to bypass multi-factor authentication and access certain company data, including personal information of residents. The company contained the incident, notified law enforcement (FBI), engaged forensic investigators, and offered identity theft protection services to affected individuals. The attack was targeted at the company itself, not specifically at individual residents' data.
- Massachusetts State AGvia Bankers Life and Casualty Company2024-01-31
Bankers Life and Casualty Company reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-01-31. 152 Massachusetts residents were affected.
- Massachusetts State AGvia WASHINGTON NATIONAL INSURANCE COMPANY2024-01-31
Washington National Insurance reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-01-31. 15 Massachusetts residents were affected.
- Maine State AGvia WASHINGTON NATIONAL INSURANCE COMPANY2024-01-30
Washington National Insurance Company reported a data breach affecting 20,360 individuals. The incident, an external system breach (hacking), occurred on November 28, 2023, and was discovered the next day. The compromised information included names and Social Security numbers. The company began notifying affected individuals on January 26, 2024, and offered 12 months of identity theft protection services.
- Montana State AGvia Bankers Life and Casualty Company2024-01-30
Bankers Life and Casualty Company notified Montana residents of a SIM swapping attack targeting a senior officer's cellular account on November 29, 2023. The threat actor bypassed MFA to access company data, potentially exposing names, SSNs, DOBs, and policy numbers. The company engaged the FBI, disabled access, reset passwords, and offered identity theft protection.
- Washington State AGvia Bankers Life and Casualty Company2024-01-30
Bankers Life and Casualty Company reported a cyberattack in Washington affecting 865 residents. A sophisticated threat actor conducted a SIM-swapping attack targeting a senior officer's cellular account on Nov 28-29, 2023, to bypass MFA and access company data. Personal info including names, SSNs, DOBs, and policy numbers may have been involved. Notices sent Jan 26, 2024.
- Maine State AGvia Bankers Life and Casualty Company2024-01-30
Bankers Life and Casualty Company reported an external system breach (hacking) on November 28, 2023, discovered on November 29, 2023. The incident affected 45,842 individuals, including 69 Maine residents. Acquired information included names and Social Security Numbers. The company provided written notification on January 26, 2024, and offered 12 months of credit monitoring and identity theft recovery services through IDX/ZeroFox.
- New Hampshire State AGvia Bankers Life and Casualty Company2024-01-30
Bankers Life and Casualty Company disclosed a security breach discovered on November 29, 2023, involving a SIM-swapping attack on a senior officer's Verizon cellular account. The threat actor, identified as 'Scattered Spider,' bypassed multi-factor authentication to access company data, potentially affecting 63 New Hampshire residents. The company contained the incident, notified law enforcement (FBI), and engaged forensic investigators. No evidence suggests customer environments were accessed or that individuals were targeted for fraud.