MILLIMAN, INC.
ent_97cb3b086a1c474f89223816
Disclosures
16
State AG · 11 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
1,000,000
nationwide · State AG CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MILLIMAN, INC.
- Normalized
- milliman— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- E26C2WHERBI2OAGBGT21
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- us.milliman.com
Disclosure history (16)newest first
- Vermont State AGas victim2024-01-12
Pension Benefit Information, LLC (PBI) notified consumers of a data breach involving Progress Software's MOVEit Transfer software. Unauthorized access occurred on May 29-30, 2023, when an attacker downloaded data from a PBI server. Progress Software disclosed the vulnerability on or around May 31, 2023. PBI patched servers, enhanced security policies, and offered 24 months of credit monitoring via Kroll. No identity theft has been confirmed.
- Maine State AGas victim2024-01-12
Milliman, Inc. reported an external system breach (hacking) occurring on May 29, 2023, discovered on May 30, 2023. The incident affected 56,457 individuals, including 224 Maine residents. Personal Identifiable Information (PII) compromised included names and Social Security Numbers. Milliman issued written notifications and provided 4 months of identity and credit monitoring through Kroll.
- Idaho State AGas reporting2023-08-18
On or around May 29-30, 2023, an unauthorized third party exploited a zero-day vulnerability (CVE-2023-34362) in Progress Software's MOVEit Transfer software, accessed by third-party vendor Pension Benefit Information, LLC (PBI). PBI stored data for client Trane Technologies. The actor downloaded personal information, including names, addresses, dates of birth, and Social Security numbers, of one Idaho resident. Trane Technologies and Milliman notified the Idaho Attorney General on August 18, 2023, and offered 24 months of credit monitoring.
- Maine State AGas victim2023-08-18
Milliman, Inc. reported an external system breach (hacking) occurring between May 29 and May 30, 2023, discovered on July 21, 2023. The incident affected 5,023 individuals, including 8 Maine residents. Personal information acquired included names and Social Security Numbers. Milliman provided 24 months of credit monitoring and identity theft protection services through Kroll.
- New Hampshire State AGas victim2023-08-17
Milliman, Inc. notified the NH AG of a data breach involving its third-party vendor, Pension Benefit Information, LLC (PBI). PBI's MOVEit Transfer software was exploited via CVE-2023-34362 (zero-day) on May 29-30, 2023. An unauthorized actor downloaded data belonging to 335 New Hampshire residents. Milliman stopped data transfers to PBI and is enhancing vendor security. PBI patched the vulnerability and offered 24 months of credit monitoring.
- California State AGas victim2023-08-14
Milliman, Inc. reported a data breach occurring between May 29 and May 30, 2023, affecting approximately 1 million individuals. The incident involved unauthorized access to personal information including names, addresses, Social Security numbers, and financial data. The company engaged forensic investigators and is offering credit monitoring services to affected individuals.
- Indiana State AGas victim2023-08-14
Milliman Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-29 and was reported on 2023-08-14. 650 Indiana residents were affected. 49,438 individuals affected in total.
- Massachusetts State AGas victim2023-08-14
Milliman, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-14. 707 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2023-08-14
Milliman, Inc., a provider of administrative services for employee benefit and pension plans, reported a data breach that occurred through a third-party vendor, Pension Benefit Information, LLC (PBI). PBI utilized the MOVEit Transfer software, which contained a zero-day vulnerability (CVE-2023-34362). Between May 29 and May 30, 2023, an unauthorized third party exploited this vulnerability to access and download data from PBI's servers. The breach was discovered on July 21, 2023, and affected personal information, including names and Social Security numbers.
- Washington State AGas victim2023-08-14
Milliman, Inc. filed a supplemental Washington state AG breach notice (ID 15644) regarding a third-party vendor (PBI) incident involving the MOVEit Transfer zero-day vulnerability (CVE-2023-34362). Unauthorized access occurred May 29-30, 2023. The breach affected 2,879 Washington residents, exposing names, addresses, DOBs, and SSNs. Notifications began August 14, 2023.
- Oregon State AGas victim2023-08-14
Milliman, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-14. The breach occurred during 5/29/2023 - 5/30/2023. The breach was discovered on 7/21/2023. 44,415 individuals were affected. Notice was sent on 8/14/2023.
- Idaho State AGas victim2023-08-14
Milliman, Inc. notified the Idaho Attorney General of a data breach involving its third-party vendor, Pension Benefit Information, LLC (PBI). PBI's MOVEit Transfer software was exploited via zero-day vulnerability CVE-2023-34362 between May 29-30, 2023. The incident affected 869 Idaho residents, exposing names, addresses, dates of birth, and Social Security numbers. PBI patched the vulnerability and offered 24 months of credit monitoring. Milliman halted data transfers to PBI and is reviewing vendor security practices.
- Montana State AGas victim2023-08-14
Milliman Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-08-14. The breach occurred from 5/29/2023 to 5/30/2023. 145 Montana residents were affected.
- New Hampshire State AGas victim2023-07-20
Milliman Solutions, LLC (dba Milliman Intelliscript) notified the NH AG of a breach involving its third-party vendor, Pension Benefit Information, LLC (PBI). PBI's MOVEit Transfer server was exploited via CVE-2023-34362 (zero-day) on May 29-30, 2023. Data of 3,036 NH residents was downloaded. Notification sent July 17, 2023, offering credit monitoring.
- Illinois State AGas victim2023-01-01
MILLIMAN, INC. filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-472). The register records the breach as discovered on May 29, 2023. Additional entities named: PENSION BENEFIT INFORMATION (PBI) LLC - LONGEVITY HOLDINGS INC., MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2023-01-01
MILLIMAN, INC. filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-551). The register records the breach as discovered on May 31, 2023. Additional entities named: PENSION BENEFIT INFORMATION (PBI) LLC - LONGEVITY HOLDINGS INC., MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
Supply-chain cascadesreviewed and confirmed
- MILLIMAN, INC.’s filing is one of at least 31 in the Pension Benefit Information, LLC supply-chain incident (2023).
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of MILLIMAN, INC. — not by MILLIMAN, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.