Ethos Technologies Inc. disclosed a cyberattack where unauthorized actors exploited its online life insurance application process to access Social Security numbers. The incident occurred between August 4, 2022, and December 9, 2022, but was not discovered until December 8, 2022. Actors used known personal information to trigger a third-party service that returned SSNs in page source code, which were then extracted. Ethos notified the FBI, engaged forensic investigators, and implemented technical code changes. Affected individuals were offered two years of credit monitoring and identity theft protection.