Prudential said MOVEit hack at vendor PBI exposed 320,840 people

Organization
The Prudential Insurance Company of America
Exploit
Supply Chain Attack
Industry
Insurance

The Prudential Insurance Company of America told regulators that personal information belonging to hundreds of thousands of current and former customers was taken in the MOVEit Transfer campaign, through a vendor rather than its own systems.

The vendor was Pension Benefit Information, a firm that performs address and death record searches for insurers and pension administrators. Attackers downloaded data from PBI's MOVEit server on May 29 and 30, 2023, days before Progress Software disclosed the underlying zero day flaw. The Clop extortion group was responsible for the wider campaign.

Prudential's first filing with the Maine attorney general put the number of affected individuals at 89. A later filing revised the figure to at least 320,840. The exposed records included names, Social Security numbers, dates of birth, phone numbers and address details. Prudential said its own information systems and operations were not affected by the incident.

Notification letters went out at the end of July 2023. PBI offered two years of credit monitoring and identity restoration through Kroll along with a dedicated call line. PBI reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights on July 14, 2023, putting the total across all of its clients at 1,209,825 individuals.

A proposed class action, Parker v. The Prudential Insurance Company of America, was filed in federal court on August 15, 2023, alleging inadequate safeguards and delayed notification.

Sources