✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Insurance
Breach intelligence, attack campaigns, and threat reports targeting the Insurance sector.
Explore Other Sectors
Insurance Threat Reports
Cybercriminals' Quest for 'Clean' Residential Proxies in Carding Schemes
In July 2026, Flare researchers analyzed 2,889 underground posts across 545 threads, revealing that cybercriminals are increasingly seeking 'clean' residential proxies to enhance their carding operations. These proxies are now part of a broader identity-simulation stack, including device fingerprints, browser profiles, and transaction behaviors, to evade detection by financial institutions. The study highlights a shift where residential IPs alone are insufficient, leading to a secondary market for proxies with pristine histories. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/inside-the-search-for-clean-residential-proxies-for-carding/?utm_source=openai)) This trend underscores the evolving tactics of cybercriminals who are investing more effort into creating convincing digital identities. The demand for 'clean' proxies indicates that traditional IP-based trust models are becoming less reliable, necessitating more comprehensive security measures. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/inside-the-search-for-clean-residential-proxies-for-carding/?utm_source=openai))
4 days ago
Kill Chain
23andMe Data Breach: A Wake-Up Call for Credential Security
In October 2023, genetic testing company 23andMe disclosed a significant data breach resulting from credential-stuffing attacks that went undetected for five months, from April to September 2023. Attackers exploited reused passwords to access approximately 14,000 user accounts, subsequently exposing sensitive genetic and personal information of 6.9 million customers. This data was later found for sale on the dark web, raising serious privacy concerns. The incident underscores the critical importance of robust cybersecurity measures, including the implementation of multi-factor authentication and proactive monitoring systems. Organizations handling sensitive data must prioritize these defenses to prevent similar breaches and protect consumer trust.
5 days ago
Kill Chain
Unimed Cyberattack 2026: A Wake-Up Call for Healthcare Vendor Security
In April 2026, Unimed, a German medical billing provider servicing numerous university hospitals, suffered a cyberattack resulting in the theft of over 72,000 patient records. The breach exposed sensitive information, including names, addresses, and health data. Unimed promptly reported the incident to authorities and collaborated with affected hospitals to notify impacted patients. The attack did not compromise the IT systems of the client hospitals, ensuring that patient care remained unaffected. ([luxgap.com](https://luxgap.com/articles/unimed-72000-patients-voles-dlp-article-32-transferts-rgpd?lang=en&utm_source=openai)) This incident underscores the critical vulnerabilities within third-party service providers in the healthcare sector. As cybercriminals increasingly target supply chains, healthcare organizations must reassess and fortify their vendor risk management and data protection strategies to prevent similar breaches.
1 week ago
Kill Chain
Scattered Spider Member Peter Stokes Extradited to US in 2026
In July 2026, Peter Stokes, a 19-year-old dual U.S.-Estonian citizen and alleged member of the cybercriminal group Scattered Spider, was extradited to the United States following his arrest in Finland. Stokes is accused of participating in multiple data theft and extortion attempts, including attacks on a luxury jewelry retailer in May 2025 and a U.S.-based insurance company in June 2025. Scattered Spider, active since 2022, has infiltrated over 100 businesses and extorted more than $100 million globally. ([cyberscoop.com](https://cyberscoop.com/scattered-spider-peter-stokes-cybercrime-extradition/?utm_source=openai)) This incident underscores the persistent threat posed by cybercriminal groups employing sophisticated social engineering tactics to infiltrate organizations. The arrest highlights the importance of robust cybersecurity measures and international cooperation in combating cybercrime.
2 weeks ago
Kill Chain
Black Basta Ransomware Group: A Comprehensive Analysis of Its Rise and Fall
Black Basta, a ransomware-as-a-service (RaaS) group, emerged in April 2022 and rapidly became a significant threat by employing double extortion tactics—encrypting victims' data and exfiltrating sensitive information to pressure organizations into paying ransoms. The group targeted over 500 organizations worldwide across various critical infrastructure sectors, including healthcare, finance, and manufacturing. Their operations involved sophisticated social engineering techniques, exploitation of known vulnerabilities, and partnerships with malware distributors like QakBot to gain initial access. In 2025, internal conflicts and law enforcement actions led to a decline in Black Basta's activities, culminating in the group's shutdown. ([techrepublic.com](https://www.techrepublic.com/article/black-basta-ransomware-attack/?utm_source=openai)) The Black Basta case underscores the evolving nature of ransomware threats, highlighting the importance of robust cybersecurity measures and proactive threat intelligence to defend against sophisticated cybercriminal operations. The group's rapid rise and eventual downfall illustrate the dynamic landscape of cyber threats and the necessity for organizations to remain vigilant and adaptable.
3 weeks ago
Kill Chain
NAIC's 2026 Data Breach: A ShinyHunters Exploit of Oracle PeopleSoft
In June 2026, the National Association of Insurance Commissioners (NAIC) experienced a cyberattack by the ShinyHunters group, who exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft servers. The attackers claimed to have stolen 3.1 TB of data, including insurer regulatory filings and AWS infrastructure configurations. NAIC's investigation indicated that only publicly available data, outdated logs, and configuration files were accessed, with no evidence of personal or financial data exposure. The breach led to operational disruptions, such as temporary suspension of data feeds by credit rating agencies and a pause in NAIC's investment designation work. This incident underscores the critical importance of promptly addressing zero-day vulnerabilities and implementing robust security measures to protect sensitive data. Organizations must remain vigilant against sophisticated threat actors like ShinyHunters, who continue to exploit unpatched systems, emphasizing the need for proactive cybersecurity strategies and timely software updates.
3 weeks ago
Kill Chain
Unveiling Mistic: The Stealthy Backdoor Linked to KongTuke
In April 2026, a new backdoor named Mistic was identified in attacks targeting organizations across the insurance, education, IT, and professional services sectors. Linked to the initial access broker KongTuke, Mistic operates entirely in memory, avoiding disk writes and incorporating a self-deletion feature to evade detection. The malware is deployed through DLL side-loading techniques, utilizing legitimate Microsoft endpoint security tools to blend in with trusted software. Once established, Mistic enables attackers to execute code, manage files, and load additional modules, facilitating long-term, low-visibility access to compromised systems. The emergence of Mistic underscores a growing trend among threat actors to develop and deploy sophisticated, stealthy malware capable of evading traditional security measures. This development highlights the need for organizations to enhance their detection and response capabilities, particularly against fileless malware that operates in memory and leverages legitimate processes to achieve persistence.
3 weeks ago
Kill Chain
Mistic Backdoor: A New Threat in Ransomware Attacks
In April 2026, a new backdoor named Mistic was identified in attacks targeting sectors such as insurance, education, IT, and professional services. Linked to the initial access broker KongTuke (also known as Woodgnat), Mistic facilitates unauthorized access to corporate networks, which is then sold to ransomware groups including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. The malware employs DLL side-loading techniques to maintain stealth and persistence, allowing attackers to execute commands, manipulate files, and exfiltrate data without detection. The emergence of Mistic underscores a growing trend where initial access brokers develop sophisticated tools to infiltrate networks, subsequently enabling ransomware operations. This development highlights the critical need for organizations to enhance their cybersecurity measures to detect and prevent such stealthy intrusions.
3 weeks ago
Kill Chain
Xsolis Data Breach 2026: A Wake-Up Call for Healthcare Cybersecurity
In January 2026, healthcare technology company Xsolis experienced a data breach affecting nearly 1.4 million individuals. The breach resulted from a targeted phishing attack on January 20, 2026, which allowed unauthorized access to Xsolis's network. The attackers accessed files containing sensitive personal and health information, including names, addresses, dates of birth, Social Security numbers, health insurance details, and medical treatment information. Xsolis detected the unauthorized activity on January 22, 2026, promptly contained the breach, and initiated an investigation with external cybersecurity experts. The company has since notified affected individuals and implemented additional security measures to prevent future incidents. This incident underscores the persistent threat of phishing attacks in the healthcare sector, highlighting the critical need for robust cybersecurity measures and employee training to protect sensitive patient data. The breach also raises concerns about potential identity theft and fraud for the affected individuals, emphasizing the importance of vigilance and proactive monitoring of personal information.
4 weeks ago
Kill Chain
SIM Swap Attack Highlights Need for Enhanced Authentication Measures
In June 2026, Torsten George, a chief cybersecurity evangelist, experienced a SIM swap attack that led to an attempted account takeover. The attacker, posing as an AT&T representative, had previously conducted a SIM swap, allowing them to intercept one-time passwords (OTPs) sent via text. During a subsequent call, the attacker sought additional credentials to gain full access to George's AT&T account. Recognizing the threat, George acted swiftly to regain control, preventing unauthorized access. This incident underscores the vulnerabilities associated with SMS-based OTPs and highlights the need for multi-layered security measures. The resurgence of SIM swap attacks, as demonstrated in this case, emphasizes the importance of adopting more secure authentication methods, such as app-based OTPs or hardware tokens, to mitigate the risks of account takeovers.
4 weeks ago
Kill Chain
Texas Parks and Wildlife Department Data Breach Exposes Over 3 Million Records
In June 2026, the Texas Parks and Wildlife Department (TPWD) disclosed a significant data breach involving its license system vendor, exposing personal information of over 3 million individuals. The compromised data includes driver's license information, passport numbers, email addresses, phone numbers, and residential addresses. Notably, Social Security numbers, dates of birth, and financial information were not affected. The breach was detected by the Texas Cyber Command, prompting an immediate investigation and the implementation of enhanced security measures. ([tpwd.texas.gov](https://tpwd.texas.gov/about/notification-of-data-security-incident/?utm_source=openai)) This incident underscores the escalating risks associated with third-party vendors in data security. Organizations are increasingly vulnerable to breaches through external partners, highlighting the necessity for stringent vendor management and comprehensive security protocols to safeguard sensitive information.
1 month ago
Kill Chain
DentaQuest Data Breach 2026: ShinyHunters Expose 2.6 Million Records
In May 2026, DentaQuest, a leading dental benefits administrator in the United States, experienced a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers infiltrated DentaQuest's network, exfiltrating over 234 GB of sensitive data, which included personal information of approximately 2.6 million individuals. The compromised data encompassed email addresses, full names, phone numbers, government-issued IDs, health insurance details, genders, and dates of birth. Following unsuccessful ransom negotiations, ShinyHunters publicly released the stolen data, amplifying the potential for identity theft and fraud among affected individuals. This incident underscores a troubling trend of cyber extortion targeting healthcare organizations, highlighting the critical need for robust cybersecurity measures and rapid incident response protocols to protect sensitive patient information.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports