ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Pan-American Life Insurance Company says MOVEit Transfer breach impacted 200,000 individuals

The Pan-American Life Insurance Company said a data security incident, which resulted from the Clop ransomware group exploiting a zero-day vulnerability in the MOVEit Transfer web application, impacted 95,000 more people than initially believed.Earlier this month, Pan-American Life Insurance Company (PALIC) said in a filing with the office of the Maine Attorney General that it used Progress Software’s MOVEit Transfer web application to send and receive files securely and was impacted after cyber criminals exploited a zero-day vulnerability in the application earlier this year.After being notified by Progress Software, the manufacturer of MOVEit software, PALIC immediately stopped using the software, secured its other systems, and launched an internal investigation with assistance from third party cyber security experts to understand the scope of the incident.The investigation revealed that the hacker group exploited vulnerabilities in the MOVEit Transfer software and accessed files that contained customers’ sensitive personal information.After concluding its investigation on October 31, PALIC determined that the compromised data included customers’ names, addresses, social security numbers, dates of birth, driver’s license numbers, contact information, medical and medical benefits information, subscriber numbers, certain biometric data, and financial account and credit card information.The insurance company in its regulatory filing revealed that at least 105,387 PALIC customers were affected by the data security incident. However, in a more recent filing with the U.S. Department of Health and Human Services Office for Civil Rights, PALIC said that 94,807 more individuals were affected by the data breach.“Immediately upon learning of this incident, we took steps to mitigate the risk to our customers and launched an investigation and recovery effort with the assistance of cybersecurity experts and law enforcement,” PALIC said.“Forensic evidence showed no unauthorised activity outside of the MOVEit application. Determining whether information was compromised in any way has been one of the top priorities of this effort so that we could notify potentially affected individuals.”PALIC added that it found no evidence of the compromised data being misused, however, the possibility of the same cannot be ruled out. The company has urged its customers to remain vigilant and keep an eye out for any suspicious activities in their credit report.The insurance company is also providing complimentary credit monitoring and identity theft restoration services for 24 months via Experian to all individuals affected by the breach.More than 2,500 organisations worldwide have so far suffered significant data breaches as a result of the Clop ransomware group exploiting vulnerabilities in Progress Software’s MOVEit Transfer web application.According to German cybersecurity research firm KonBriefing, as of December 11, at least 2,601 organisations worldwide have suffered security incidents resulting from the exploitation of the software and up to 83 million individuals have been impacted so far.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543