NATIONAL NEWS

2.5M Genworth policyholders and 769K retired California workers and beneficiaries affected by hack

Jun 22, 2023, 1:12 PM | Updated: 5:26 pm

SACRAMENTO, Calif. (AP) — The country’s largest public pension fund says the personal information of about 769,000 retired California employees and other beneficiaries — including Social Security numbers — was among data stolen by Russian cybercriminals in the breach of a popular file-transfer application.

It blamed the breach on a third-party vendor that verifies deaths. The same vendor, PBI Research Services/Berwyn Group, also lost the personal data of at least 2.5 million Genworth Financial policyholders, including Social Security numbers, to the same criminal gang, according to the Fortune 500 insurer.

The California Public Employees Retirement system said they were offering affected members two years of free credit monitoring. Genworth said in a statement posted online it would offer credit monitoring and ID theft protection.

The breach of the MOVEit file-transfer program, discovered last month, is estimated by cybersecurity experts to have compromised hundreds of organizations globally. Confirmed victims include the U.S. Department of Energy and several other federal agencies, more than 9 million motorists in Oregon and Louisiana, Johns Hopkins University, Ernst & Young, the BBC and British Airways.

The criminal gang behind the hack, known as Cl0p, is extorting victims, threatening to dump their data online if they don’t pay up.

Genworth disclosed the hack Thursday of the MOVEit instance managed by PBI Research in a filing with the Securities and Exchange Commission.

Minnesota-based PBI Research did not immediately return a phone message seeking details on which of its other customers may have been affected. The company’s website lists the Nevada, New Jersey and Tennessee public pension funds as among customers of its mortality verification service.

“This external breach of information is inexcusable,” CalPERS CEO Marcie Frost said in a news release. “Our members deserve better. As soon as we learned about what happened, we took fast action to protect our members’ financial interests, as well as steps to ensure long-term protections.”

CalPERS had more than $442 billion in assets as of Dec. 31 and about 1.5 million members.

Security experts say such so-called supply-chain hacks expose an uncomfortable truth about the software organizations use: Network security is only as strong as the weakest digital link in the ecosystem.

The stolen data included names, birth dates and Social Security numbers — and might also include names of spouses or domestic partners and children, officials said. CalPERS planned to send letters Thursday to those affected by the breach.

CalPERS said PBI notified it of the breach on June 6, the same day cybersecurity firms began to issue reports on the breach of MOVEit, whose maker, Ipswitch, is owned by Progress Software.

PBI reported the breach to federal law enforcement, and CalPERS placed “additional safeguards” to protect the information of retirees who use the member benefits website and visit a regional office, officials said. The agency did not elaborate on those safeguards, citing security reasons.

___

This story has been corrected to reflect that Genworth disclosed the hack on Thursday, not June 16.

___

Bajak reported from Boston.

___

Sophie Austin is a corps member for the Associated Press/Report for America Statehouse News Initiative. Report for America is a nonprofit national service program that places journalists in local newsrooms to report on undercovered issues. Follow Austin on Twitter: @sophieadanna

National News

FILE - Traffic streaks by the Cuban Embassy in Washington early Saturday morning, Nov. 26, 2016. U....

Associated Press

Molotov cocktail is thrown at the Cuban Embassy in Washington, but there’s no damage and no injuries

WASHINGTON (AP) — At least one Molotov cocktail was thrown at the Cuban Embassy in Washington, but there was no significant damage and no one was injured. U.S. law enforcement officials were investigating. Secret Service officers were called around 8 p.m. Sunday to respond to the attack on a busy street in the Adams-Morgan section […]

3 hours ago

FILE - The Amazon app is seen on a smartphone, Tuesday, Feb. 28, 2023, in Marple Township, Pa. Afte...

Associated Press

Amazon is investing up to $4 billion in AI startup Anthropic in growing tech battle

Amazon is investing up to $4 billion in Anthropic and taking a minority stake in the artificial intelligence startup, the two companies said Monday.

3 hours ago

Associated Press

South Carolina high school mourns after shooting kills 3 teenage students

COLUMBIA, S.C. (AP) — A South Carolina high school is in mourning after three teenage students were killed in a weekend shooting. Sheriff’s deputies responded to the shooting in Columbia, the state capital, just after 2 p.m. Sunday, the Richland County Sheriff’s Department said in a news release. They found four people with gunshot wounds, […]

3 hours ago

FILE - A passenger disembarks from Amtrak's Sunset Limited at its final stop in New Orleans, Nov. 2...

Associated Press

Biden administration announces $1.4 billion to improve rail safety and boost capacity in 35 states

WASHINGTON (AP) — The Biden administration announced Monday that it has awarded more than $1.4 billion to projects that improve railway safety and boost capacity, with much of the money coming from the 2021 infrastructure law. “These projects will make American rail safer, more reliable, and more resilient, delivering tangible benefits to dozens of communities […]

7 hours ago

FILE - Sweat covers the face of Juan Carlos Biseno after dancing to music from his headphones as af...

Associated Press

After summer’s extreme weather, more Americans see climate change as a culprit, AP-NORC poll shows

Kathleen Maxwell has lived in Phoenix for more than 20 years, but this summer was the first time she felt fear, as daily high temperatures soared to 110 degrees or hotter and kept it up for a record-shattering 31 consecutive days. “It’s always been really hot here, but nothing like this past summer,” said Maxwell, […]

9 hours ago

Hudson, 7, left, Callahan, 13, middle, and Keegan Pruente, 10, right, stand outside their school on...

Associated Press

More schools are adopting 4-day weeks. For parents, the challenge is day 5

INDEPENDENCE, Mo. (AP) — It’s a Monday in September, but with schools closed, the three children in the Pruente household have nowhere to be. Callahan, 13, contorts herself into a backbend as 7-year-old Hudson fiddles with a balloon and 10-year-old Keegan plays the piano. Like a growing number of students around the U.S, the Pruente […]

10 hours ago

Sponsored Articles

Swedish Cyberknife...

September is Prostate Cancer Awareness Month

September is a busy month on the sports calendar and also holds a very special designation: Prostate Cancer Awareness Month.

Ziply Fiber...

Dan Miller

The truth about Gigs, Gs and other internet marketing jargon

If you’re confused by internet technologies and marketing jargon, you’re not alone. Here's how you can make an informed decision.

Education families...

Education that meets the needs of students, families

Washington Virtual Academies (WAVA) is a program of Omak School District that is a full-time online public school for students in grades K-12.

Emergency preparedness...

Emergency planning for the worst-case scenario

What would you do if you woke up in the middle of the night and heard an intruder in your kitchen? West Coast Armory North can help.

Innovative Education...

The Power of an Innovative Education

Parents and students in Washington state have the power to reimagine the K-12 educational experience through Insight School of Washington.

Medicare fraud...

If you’re on Medicare, you can help stop fraud!

Fraud costs Medicare an estimated $60 billion each year and ultimately raises the cost of health care for everyone.

2.5M Genworth policyholders and 769K retired California workers and beneficiaries affected by hack