Desk live·
ForensicPost
Insurance/Identity/File 24-0213

Prudential Said No Customer Data Was Taken; Four Months Later It Notified 2,556,210 People

The Form 8-K of Feb. 13, 2024, described access to administrative data and a small share of staff accounts. ALPHV claimed the intrusion the same day. A Maine filing in March said 36,000; an amended one in June said 2.5 million, with driver’s license numbers in scope.

Constructed geometry · not a chart of case data
JurisdictionUSANewarkthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetPrudential Financial
ActorALPHV (claimed)
D. Kennedy9 min readConfidence: high3 sources reviewed

Prudential Financial reported to the Securities and Exchange Commission on Feb. 13, 2024, that beginning Feb. 4 a threat actor had gained access to some of its systems, reached administrative and user data and a small percentage of employee and contractor accounts, and that the company had no evidence customer or client data had been taken. It had detected the intrusion on Feb. 5. The same day as the filing, the ALPHV ransomware operation listed Prudential on its leak site.

The company’s first filing with the Maine attorney general, in late March, said about 36,000 people were affected. An amended filing in late June raised that to 2,556,210. The fields were names, addresses and driver’s license or non-driver identification numbers.

Three Statements About The Same Event

The 8-K said no evidence of customer data theft. The first Maine filing said 36,000. The second said 2.5 million. Each was presumably accurate on its date, and the sequence is what the corpus describes at 26-0425: a disclosure is a snapshot of what the investigation has established, and early snapshots are small. What is unusual here is the first statement’s confidence. An investor filing that says no evidence, issued nine days after detection, was read by markets as a finding. It was a status.

The Operator Collapsed Before The Victim Finished Counting

ALPHV shut down in March 2024, after the Change Healthcare payment filed at 24-0301, taking the affiliate’s share and disappearing. Whatever the group held from Prudential went with it. The claim was never verified beyond the listing, and Prudential said only that the actor was suspected to be a cybercrime group. No ransom was reported paid.

The class action in New Jersey settled for $4.75 million with preliminary approval in June 2025 and a final hearing in October. Payments were up to $5,000 for documented losses and $200 to $599 for those whose Social Security or tax numbers were exposed, a category the settlement notices include and the company’s own filings do not. No regulator penalty was found.

How we reported this

Compiled from Prudential’s Form 8-K, its Maine filings as reported and contemporaneous coverage, listed below. The 2,556,210 figure is the company’s amended filing. Field lists beyond the company’s own are from settlement notices and are marked as such. ALPHV’s claim is unverified beyond the listing. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Prudential Financial, Inc., Form 8-K, Feb. 13, 2024U.S. Securities and Exchange Commission
  2. Prudential Financial now says 2.5 million impacted by data breachBleepingComputer
  3. Prudential Financial Data Breach Impacts 36,000SecurityWeek
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary