MILLIMAN, INC.
ent_97cb3b086a1c474f89223816
Disclosures
12
State AG · 8 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
1,000,000
nationwide · State AG CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MILLIMAN, INC.
- Normalized
- milliman— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- E26C2WHERBI2OAGBGT21
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- us.milliman.com
Disclosure history (12)newest first
- Vermont State AGas victim2024-01-12
Milliman notified the Vermont Attorney General that unauthorized access occurred via a vulnerability in Progress Software's MOVEit Transfer file transfer application. Personal information of Vermont residents, including names, addresses, dates of birth, and potentially Social Security numbers and health data, was accessed and exfiltrated. Milliman engaged forensic experts and is offering credit monitoring to affected individuals.
- Maine State AGas victim2024-01-12
Milliman, Inc. reported an external system breach (hacking) occurring on May 29, 2023, discovered on May 30, 2023. The incident affected 56,457 individuals, including 224 Maine residents. Personal Identifiable Information (PII) compromised included names and Social Security Numbers. Milliman issued written notifications and provided 4 months of identity and credit monitoring through Kroll.
- Idaho State AGas reporting2023-08-18
On or around May 29-30, 2023, an unauthorized third party exploited a zero-day vulnerability (CVE-2023-34362) in Progress Software's MOVEit Transfer software, accessed by third-party vendor Pension Benefit Information, LLC (PBI). PBI stored data for client Trane Technologies. The actor downloaded personal information, including names, addresses, dates of birth, and Social Security numbers, of one Idaho resident. Trane Technologies and Milliman notified the Idaho Attorney General on August 18, 2023, and offered 24 months of credit monitoring.
- Maine State AGas victim2023-08-18
Milliman, Inc. reported an external system breach (hacking) occurring between May 29 and May 30, 2023, discovered on July 21, 2023. The incident affected 5,023 individuals, including 8 Maine residents. Personal information acquired included names and Social Security Numbers. Milliman provided 24 months of credit monitoring and identity theft protection services through Kroll.
- New Hampshire State AGas victim2023-08-17
Milliman, Inc. notified the NH AG of a data breach involving its third-party vendor, Pension Benefit Information, LLC (PBI). PBI's MOVEit Transfer software was exploited via CVE-2023-34362 (zero-day) on May 29-30, 2023. An unauthorized actor downloaded data belonging to 335 New Hampshire residents. Milliman stopped data transfers to PBI and is enhancing vendor security. PBI patched the vulnerability and offered 24 months of credit monitoring.
- California State AGas victim2023-08-14
Milliman, Inc. reported a data breach occurring between May 29 and May 30, 2023, affecting approximately 1 million individuals. The incident involved unauthorized access to personal information including names, addresses, Social Security numbers, and financial data. The company engaged forensic investigators and is offering credit monitoring services to affected individuals.
- Massachusetts State AGas victim2023-08-14
Milliman, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-14. 707 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2023-08-14
Milliman, Inc., a provider of administrative services for employee benefit and pension plans, reported a data breach that occurred through a third-party vendor, Pension Benefit Information, LLC (PBI). PBI utilized the MOVEit Transfer software, which contained a zero-day vulnerability (CVE-2023-34362). Between May 29 and May 30, 2023, an unauthorized third party exploited this vulnerability to access and download data from PBI's servers. The breach was discovered on July 21, 2023, and affected personal information, including names and Social Security numbers.
- Oregon State AGas victim2023-08-14
Milliman, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-14. The breach occurred during 5/29/2023 - 5/30/2023. The breach was discovered on 7/21/2023. 44,415 individuals were affected. Notice was sent on 8/14/2023.
- Idaho State AGas victim2023-08-14
Milliman, Inc. notified the Idaho Attorney General of a data breach involving its third-party vendor, Pension Benefit Information, LLC (PBI). PBI's MOVEit Transfer software was exploited via zero-day vulnerability CVE-2023-34362 between May 29-30, 2023. The incident affected 869 Idaho residents, exposing names, addresses, dates of birth, and Social Security numbers. PBI patched the vulnerability and offered 24 months of credit monitoring. Milliman halted data transfers to PBI and is reviewing vendor security practices.
- Montana State AGas victim2023-08-14
Milliman Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-08-14. The breach occurred from 5/29/2023 to 5/30/2023. 145 Montana residents were affected.
- New Hampshire State AGas victim2023-07-20
Milliman Solutions, LLC (dba Milliman Intelliscript) notified the NH AG of a breach involving its third-party vendor, Pension Benefit Information, LLC (PBI). PBI's MOVEit Transfer server was exploited via CVE-2023-34362 (zero-day) on May 29-30, 2023. Data of 3,036 NH residents was downloaded. Notification sent July 17, 2023, offering credit monitoring.
Supply-chain cascadesreviewed and confirmed
- MILLIMAN, INC.’s filing is one of at least 27 in the Pension Benefit Information, LLC supply-chain incident (2023).
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of MILLIMAN, INC. — not by MILLIMAN, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.