
The New York Life Insurance Company, one of the largest life insurance companies in the United States, said it suffered a major data breach that affected the personal information of more than 35,000 individuals.In a recent filing with the Office of the Maine Attorney General, the insurance provider said that one of its vendors, Pension Benefit Information, suffered a massive cyber security incident as a result of the Clop ransomware group exploiting a zero-day vulnerability in the MOVEit Transfer web application.PBI provides regulatory compliance and operational support services for insurance companies, pension funds, and other organisations, including the New York Life Insurance Company. PBI used Progress Software’s MOVEit file transfer application to send and receive data from some of its clients and was affected by malicious exploitation of a zero-day vulnerability in the file transfer software.Soon after PBI became aware of the security incident involving the MOVEit file transfer application, it launched an internal investigation to understand the nature and scope of the security incident.“Through our investigation, we learned that the third party accessed one of our MOVEit Transfer servers on May 29, 2023 and May 30, 2023 and downloaded data. We then conducted a manual review of our records to confirm the identities of individuals potentially affected by this event and their contact information to provide notifications. We recently completed this review and shared the findings with our impacted customers,” the company said.The compromised information included the full names of New York Life Insurance Company’s customers along with their Social security Numbers and other personal identifier data. The insurance provider has so far made three filings with the Office of the Maine Attorney general to update the number of affected customers.While the insurance giant’s first filing said that 1,367 individuals were impacted by the data breach, the second filing revised the figure to 25,685, and the last filing added another 35,062 individuals to the list of affected individuals.PBI says it is providing two years of complimentary credit monitoring, fraud consultation and identity restoration services through Kroll to all affected individuals and has set up a hotline where impacted clients can call and get their queries answered.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543