Prudential said MOVEit hack at vendor PBI exposed 320,840 people
- Organization
- The Prudential Insurance Company of America
- Exploit
- Supply Chain Attack
- Industry
- Insurance
The Prudential Insurance Company of America told regulators that personal information belonging to hundreds of thousands of current and former customers was taken in the MOVEit Transfer campaign, through a vendor rather than its own systems.
The vendor was Pension Benefit Information, a firm that performs address and death record searches for insurers and pension administrators. Attackers downloaded data from PBI's MOVEit server on May 29 and 30, 2023, days before Progress Software disclosed the underlying zero day flaw. The Clop extortion group was responsible for the wider campaign.
Prudential's first filing with the Maine attorney general put the number of affected individuals at 89. A later filing revised the figure to at least 320,840. The exposed records included names, Social Security numbers, dates of birth, phone numbers and address details. Prudential said its own information systems and operations were not affected by the incident.
Notification letters went out at the end of July 2023. PBI offered two years of credit monitoring and identity restoration through Kroll along with a dedicated call line. PBI reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights on July 14, 2023, putting the total across all of its clients at 1,209,825 individuals.
A proposed class action, Parker v. The Prudential Insurance Company of America, was filed in federal court on August 15, 2023, alleging inadequate safeguards and delayed notification.
Sources
- teiss, Prudential Insurance Company of America says MOVEit Transfer hack impacted 320k customers
- ClassAction.org, Class Action Filed Over Prudential Data Breach Affecting Over 300K Consumers
- The HIPAA Journal, Pension Benefit Information Confirms PHI of 1.2 Million Individuals Stolen in MOVEit Transfer Hack