PBI Research Services (PBI) suffered a data breach, with three clients revealing that the data of 4.75 million people was stolen during the recent MOVEit Transfer data theft attacks.

These attacks began on May 27, 2023, when the Clot ransomware gang started exploiting a zero-day vulnerability in MOVEit Transfer, allegedly stealing data from hundreds of companies.
Over the past week, the Clop gang has begun blackmailing companies by slowly listing the organizations affected by the data breach on its website, in an attempt to pressure victims into paying a ransom.
According to three separate disclosures from PBI customers, the data of millions of customers has been exposed in these attacks - however, this number may increase as other companies make further disclosures.
The first entity affected is Genworth Financial, a life insurance services provider headquartered in Virginia.
In a MOVEit security incident notification posted on its website, Genworth states that PBI informed it of the security breach on May 29, 2023, and confirmed on June 16 that customers' personal data had been stolen.

The company estimates that the data breach affected 2.5 to 2.7 million people who are either its customers (insurance, pensions and long‑term care) or work for it as insurance agents.
The exposed data includes the following:
- Full name
- Date of birth
- Social Security Number
- Postal code
- Country of residence
- Policy number
Genworth states that this attack had no impact on its systems and networks or its business operations, as it does not use the MOVEit or GoAnywhere products.
The affected individuals will receive notifications regarding the data breach in the coming weeks, which will contain instructions for signing up for free credit monitoring and identity theft protection services.
The second company affected by the PBI breach is Wilton Reassurance, an insurance company based in New York, which reports that the data of 1.482.490 of its customers were stolen.
The Office of the Maine Attorney General reported that the exposed information includes customer names and Social Security numbers.
Although a sample data breach notification letter has not yet been posted on the Maine portal, Wilton Reassurance has advised that it will provide affected individuals with 12 months of free identity theft protection and credit monitoring services through Kroll.
The third company affected by the PBI data breach is CalPERS (California Public Employees’ Retirement System), the largest public pension fund in the United States, which is now informing its retirees and beneficiaries about the incident.
In a statement posted on its website, CalPERS said it responded immediately upon learning of the breach and took steps to secure its members' benefits and data by strengthening data management protocols related to working with contractors.
The organization says that approximately 769,000 of its members were affected by the security incident, and all will receive notification letters with detailed information on how to access two years of free credit monitoring service through Experian.
At this time, PBI Research Services has not yet been listed on Clop. While this could mean that the company is negotiating with the threat actors to not release data, it could also mean that Clop has not yet started blackmailing the organization.
Information source: bleepingcomputer.com
