Sun Life US members exposed in MOVEit breach at vendor PBI

Organization
Sun Life Financial
Exploit
Third-Party Data Breach
Industry
Insurance

Sun Life told US members and account holders in July 2023 that some of their personal information had been taken in the MOVEit campaign, through a vendor rather than through Sun Life itself. The insurer said it was not a MOVEit customer and that its own systems, networks and business operations were not directly affected.

The vendor was Pension Benefit Information LLC, known as PBI, which provides compliance and operational support to insurers and pension funds. PBI told Sun Life in late June 2023 that one of its servers had been accessed by an unauthorized third party. The access took place on May 29 and 30, 2023, before Progress Software disclosed the underlying MOVEit Transfer vulnerability. The Cl0p ransomware group ran the campaign.

Sun Life said the data involved could include names, Social Security numbers, policy and account numbers and dates of birth, with the combination varying by individual. It said no financial information such as account values, and no medical claims data, was exposed. The affected records covered group life, long term disability, life premium waiver, individual life and group pension annuity business.

Sun Life conducted a manual review of its records to confirm who was affected and how to reach them before issuing notifications, and posted a notice on its website on July 13, 2023. PBI offered two years of credit monitoring, fraud consultation and identity restoration services through Kroll. Sun Life later reported the total to the Maine attorney general as 212,129 individuals.

Sources