Prudential Financial disclosed breach of employee and contractor data
- Organization
- Prudential Financial
- Exploit
- Ransomware
- Industry
- Financial Services
Prudential Financial disclosed in a filing with the U.S. Securities and Exchange Commission in mid-February 2024 that an intruder had reached some of its systems. The company said unauthorized access began on February 4 and was detected the following day, and that it immediately activated its cybersecurity incident response process with help from outside experts.
According to the filing, the attacker took administrative and user data from certain information technology systems and reached a small percentage of company user accounts belonging to employees and contractors. Prudential said it had found no evidence that customer or client data had been taken, and did not expect the incident to have a material effect on its operations or financial results. Commentators noted the disclosure appeared to be voluntary, made ahead of any materiality determination.
On February 16, 2024 the ALPHV/BlackCat ransomware operation claimed responsibility, saying it retained access and was weighing whether to sell the stolen data or publish it. The same group had claimed the January 2024 intrusion at mortgage lender loanDepot.
Prudential later began notifying 36,545 individuals, telling regulators the exposed information consisted of names together with driver's license numbers or non-driver identification card numbers. Those notifications went out at the end of March 2024.
Updates
-
Prudential revised its filing with the Maine Attorney General on 28 June 2024, putting the total at 2,556,210 people, up from the 36,545 notified in March. The revised notice added driver's licence numbers and identification card numbers to the exposed data and covers the same 4 February 2024 intrusion.