Ransomware
Prudential Financial ALPHV/BlackCat Breach
Primary Source βIncident Details
ALPHV/BlackCat ransomware group breached Prudential Financial (major US insurer) between 4-5 February 2024, initially believed to affect only 36,545 people. The true scope was revealed in July 2024 as 2,556,210 individuals’ names, addresses, and driver’s license/non-driver ID numbers were compromised. ALPHV publicly claimed the breach on 16 February 2024 after Prudential refused to pay ransom. Prudential settled class action litigation for $4.75 million and offered 24 months of Kroll credit monitoring.
Technical Details
- Initial Attack Vector
- ALPHV/BlackCat ransomware gained unauthorized access to Prudential Financial administrative and user data; initial access vector not publicly disclosed
- Malware Family
- ALPHV/BlackCat
Timeline
- 2024-02-04 Breach occurred
- 2024-02-13 Publicly disclosed
- 2024-03-01 Customers notified