Corebridge Financial, Inc. disclosed a security incident involving a third-party vendor's MOVEit Transfer instance. The vendor exploited a zero-day vulnerability, compromising customer data including Social Security numbers and policy numbers. Corebridge launched an investigation, notified regulators, and offered credit monitoring services. The incident did not impact Corebridge's own systems.