Incident

Metropolitan Life Insurance Company reports data breach caused by third party compromise


Learn More

Metropolitan Life Insurance Company ("MetLife") is reporting a data breach following a cyberattack on one of its service providers.

The breach was first detected on February 22, 2024, when the service provider identified unauthorized access to its IT network. After securing the system and launching an internal investigation, the provider confirmed in June 2024 that confidential data related to MetLife customers had been compromised.

MetLife was informed of the breach in July 2024 and subsequently conducted its own review of the compromised files to determine the specific information affected.

This incident allowed an unauthorized party to access sensitive consumer data, including:

  • Names
  • Dates of birth
  • Policy numbers
  • Social Security numbers

After completing its investigation, MetLife began sending out notification letters on August 28, 2024, to individuals impacted by the breach. The number of affected individuals, the nature of the attack and the compromised provider are not disclosed.

Metropolitan Life Insurance Company reports data breach caused by third party compromise