2.5M Genworth policyholders and 769K retired California workers and beneficiaries affected by hack

Advertisement

Advertise with us

SACRAMENTO, Calif. (AP) — The country's largest public pension fund says the personal information of about 769,000 retired California employees and other beneficiaries — including Social Security numbers — was among data stolen by Russian cybercriminals in the breach of a popular file-transfer application.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 22/06/2023 (1196 days ago), so information in it may no longer be current.

SACRAMENTO, Calif. (AP) — The country’s largest public pension fund says the personal information of about 769,000 retired California employees and other beneficiaries — including Social Security numbers — was among data stolen by Russian cybercriminals in the breach of a popular file-transfer application.

It blamed the breach on a third-party vendor that verifies deaths. The same vendor, PBI Research Services/Berwyn Group, also lost the personal data of at least 2.5 million Genworth Financial policyholders, including Social Security numbers, to the same criminal gang, according to the Fortune 500 insurer.

The California Public Employees Retirement system said they were offering affected members two years of free credit monitoring. Genworth said in a statement posted online it would offer credit monitoring and ID theft protection.

FILE - The suns peaks over the California Public Employees Retirement System's building in Sacramento, Calif., on Sept. 6, 2022. California officials say the personal information of about 769,000 people has been exposed in a third-party data breach linked to the state's retirement system. (AP Photo/Rich Pedroncelli, File)
FILE - The suns peaks over the California Public Employees Retirement System's building in Sacramento, Calif., on Sept. 6, 2022. California officials say the personal information of about 769,000 people has been exposed in a third-party data breach linked to the state's retirement system. (AP Photo/Rich Pedroncelli, File)

The breach of the MOVEit file-transfer program, discovered last month, is estimated by cybersecurity experts to have compromised hundreds of organizations globally. Confirmed victims include the U.S. Department of Energy and several other federal agencies, more than 9 million motorists in Oregon and Louisiana, Johns Hopkins University, Ernst & Young, the BBC and British Airways.

The criminal gang behind the hack, known as Cl0p, is extorting victims, threatening to dump their data online if they don’t pay up.

Genworth disclosed the hack Thursday of the MOVEit instance managed by PBI Research in a filing with the Securities and Exchange Commission.

Minnesota-based PBI Research did not immediately return a phone message seeking details on which of its other customers may have been affected. The company’s website lists the Nevada, New Jersey and Tennessee public pension funds as among customers of its mortality verification service.

“This external breach of information is inexcusable,” CalPERS CEO Marcie Frost said in a news release. “Our members deserve better. As soon as we learned about what happened, we took fast action to protect our members’ financial interests, as well as steps to ensure long-term protections.”

CalPERS had more than $442 billion in assets as of Dec. 31 and about 1.5 million members.

Security experts say such so-called supply-chain hacks expose an uncomfortable truth about the software organizations use: Network security is only as strong as the weakest digital link in the ecosystem.

The stolen data included names, birth dates and Social Security numbers — and might also include names of spouses or domestic partners and children, officials said. CalPERS planned to send letters Thursday to those affected by the breach.

CalPERS said PBI notified it of the breach on June 6, the same day cybersecurity firms began to issue reports on the breach of MOVEit, whose maker, Ipswitch, is owned by Progress Software.

PBI reported the breach to federal law enforcement, and CalPERS placed “additional safeguards” to protect the information of retirees who use the member benefits website and visit a regional office, officials said. The agency did not elaborate on those safeguards, citing security reasons.

___

This story has been corrected to reflect that Genworth disclosed the hack on Thursday, not June 16.

___

Bajak reported from Boston.

___

Sophie Austin is a corps member for the Associated Press/Report for America Statehouse News Initiative. Report for America is a nonprofit national service program that places journalists in local newsrooms to report on undercovered issues. Follow Austin on Twitter: @sophieadanna

Report Error Submit a Tip

More Stories

Is another goalie on Jets’ wish list?

Ken Wiebe 7 minute read Preview

Is another goalie on Jets’ wish list?

Ken Wiebe 7 minute read Sunday, Sep. 27, 2026

Kevin Cheveldayoff and company are down to the short strokes.

With the opening-day roster due on Monday afternoon, the Winnipeg Jets took steps on the weekend to get down to the final number.

As it stood on Sunday, the Jets were down to 24 healthy players in training camp after centre Danny Zhilkin and defenceman Henry Thrun were placed on waivers.

With a maximum of 23 spots available, the only things left to determine are whether the Jets are interested in claiming a more experienced goalie to serve as the backup to Stuart Skinner and if centre Brayden Yager will break camp with the big club.

Read
Sunday, Sep. 27, 2026

Hydro reports $446-M loss in 2025-26, points to fourth drought year in past five

Scott Billeck 3 minute read Preview

Hydro reports $446-M loss in 2025-26, points to fourth drought year in past five

Scott Billeck 3 minute read 6:38 PM CDT

Manitoba Hydro posted a $446-million loss in 2025-26, as drought conditions slashed hydroelectric generation, forcing the Crown corporation to buy more power while leaving it with less electricity to sell outside the province.

The loss was $666 million worse than the $220-million profit Hydro had budgeted. The utility posted a $63-million loss the previous year, according to the utility’s annual report released Tuesday.

Hydro said the 2025-26 fiscal year, which ended on March 31, marked its fourth low-water year in the past five years, among the worst stretches of water-flow conditions in its recorded history.

Hydroelectric generation fell 23 per cent to 24 billion kilowatt-hours from 31 billion the previous year, leaving Hydro a net importer of electricity.

Read
6:38 PM CDT

Hero fought to remember children lost at residential school

Niigaan Sinclair 5 minute read Preview

Hero fought to remember children lost at residential school

Niigaan Sinclair 5 minute read 6:25 PM CDT

The story of the gravesites of students who attended the Brandon Indian Residential School underneath the Turtle Crossing Campground is truly a Manitoba tragedy.

Read
6:25 PM CDT

Uncaring hubby fell flat at first hurdle

Maureen Scurfield 4 minute read Yesterday at 2:00 AM CDT

DEAR MISS LONELYHEARTS: I re-rented my favourite summer cabin this fall because I’m trying to finish my thesis. My husband of just over a year was very annoyed with me for going on my own, but didn’t say much about it because I paid.

I thought we were both OK with this arrangement, until I got the flu up at the lake very badly and couldn’t keep anything down. I felt faint. I phoned him and he said he was at a party with the guys. I could hear music and girls laughing.

He wouldn’t come for me, so at 4 a.m. when I was getting even more sick and scared, I drove back to the city unannounced.

I went straight to my parents’ house and pretty much fell through the door. Mom said to me when she grabbed me: “This is not right. You could have died in the ditch. Where is your husband?”

2.5M Genworth policyholders and 769K retired California workers and beneficiaries affected by hack

Sophie Austin And Frank Bajak, The Associated Press 3 minute read Preview

2.5M Genworth policyholders and 769K retired California workers and beneficiaries affected by hack

Sophie Austin And Frank Bajak, The Associated Press 3 minute read Thursday, Jun. 22, 2023

SACRAMENTO, Calif. (AP) — The country's largest public pension fund says the personal information of about 769,000 retired California employees and other beneficiaries — including Social Security numbers — was among data stolen by Russian cybercriminals in the breach of a popular file-transfer application.

It blamed the breach on a third-party vendor that verifies deaths. The same vendor, PBI Research Services/Berwyn Group, also lost the personal data of at least 2.5 million Genworth Financial policyholders, including Social Security numbers, to the same criminal gang, according to the Fortune 500 insurer.

The California Public Employees Retirement system said they were offering affected members two years of free credit monitoring. Genworth said in a statement posted online it would offer credit monitoring and ID theft protection.

The breach of the MOVEit file-transfer program, discovered last month, is estimated by cybersecurity experts to have compromised hundreds of organizations globally. Confirmed victims include the U.S. Department of Energy and several other federal agencies, more than 9 million motorists in Oregon and Louisiana, Johns Hopkins University, Ernst & Young, the BBC and British Airways.

Read
Thursday, Jun. 22, 2023

Khan cites infighting, quits as Tory leader

Carol Sanders 5 minute read Preview

Khan cites infighting, quits as Tory leader

Carol Sanders 5 minute read Updated: 9:56 AM CDT

Manitoba’s Leader of the Opposition is stepping down.

Progressive Conservative Leader Obby Khan announced late Monday afternoon he is quitting caucus and will sit in the legislature as an independent MLA, effective today.

He cited internal party fighting for his decision.

The former Winnipeg Blue Bombers offensive lineman survived a caucus confidence vote Friday. He said there were 13 votes for him to remain and six against, with one person absent.

Read
Updated: 9:56 AM CDT