The Containment Era is here. →Explore

Industry Category

Insurance

Breach intelligence, attack campaigns, and threat reports targeting the Insurance sector.

55 threat reports
Page 1 of 5

Explore Other Sectors

Accounting
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Insurance Threat Reports

Showing 112 / 55 reports
Cybercriminals' Quest for 'Clean' Residential Proxies in Carding Schemes
Impact· MEDIUM

Cybercriminals' Quest for 'Clean' Residential Proxies in Carding Schemes

In July 2026, Flare researchers analyzed 2,889 underground posts across 545 threads, revealing that cybercriminals are increasingly seeking 'clean' residential proxies to enhance their carding operations. These proxies are now part of a broader identity-simulation stack, including device fingerprints, browser profiles, and transaction behaviors, to evade detection by financial institutions. The study highlights a shift where residential IPs alone are insufficient, leading to a secondary market for proxies with pristine histories. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/inside-the-search-for-clean-residential-proxies-for-carding/?utm_source=openai)) This trend underscores the evolving tactics of cybercriminals who are investing more effort into creating convincing digital identities. The demand for 'clean' proxies indicates that traditional IP-based trust models are becoming less reliable, necessitating more comprehensive security measures. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/inside-the-search-for-clean-residential-proxies-for-carding/?utm_source=openai))

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
23andMe Data Breach: A Wake-Up Call for Credential Security
Impact· HIGH

23andMe Data Breach: A Wake-Up Call for Credential Security

In October 2023, genetic testing company 23andMe disclosed a significant data breach resulting from credential-stuffing attacks that went undetected for five months, from April to September 2023. Attackers exploited reused passwords to access approximately 14,000 user accounts, subsequently exposing sensitive genetic and personal information of 6.9 million customers. This data was later found for sale on the dark web, raising serious privacy concerns. The incident underscores the critical importance of robust cybersecurity measures, including the implementation of multi-factor authentication and proactive monitoring systems. Organizations handling sensitive data must prioritize these defenses to prevent similar breaches and protect consumer trust.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Unimed Cyberattack 2026: A Wake-Up Call for Healthcare Vendor Security
Impact· HIGH

Unimed Cyberattack 2026: A Wake-Up Call for Healthcare Vendor Security

In April 2026, Unimed, a German medical billing provider servicing numerous university hospitals, suffered a cyberattack resulting in the theft of over 72,000 patient records. The breach exposed sensitive information, including names, addresses, and health data. Unimed promptly reported the incident to authorities and collaborated with affected hospitals to notify impacted patients. The attack did not compromise the IT systems of the client hospitals, ensuring that patient care remained unaffected. ([luxgap.com](https://luxgap.com/articles/unimed-72000-patients-voles-dlp-article-32-transferts-rgpd?lang=en&utm_source=openai)) This incident underscores the critical vulnerabilities within third-party service providers in the healthcare sector. As cybercriminals increasingly target supply chains, healthcare organizations must reassess and fortify their vendor risk management and data protection strategies to prevent similar breaches.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Scattered Spider Member Peter Stokes Extradited to US in 2026
Impact· HIGH

Scattered Spider Member Peter Stokes Extradited to US in 2026

In July 2026, Peter Stokes, a 19-year-old dual U.S.-Estonian citizen and alleged member of the cybercriminal group Scattered Spider, was extradited to the United States following his arrest in Finland. Stokes is accused of participating in multiple data theft and extortion attempts, including attacks on a luxury jewelry retailer in May 2025 and a U.S.-based insurance company in June 2025. Scattered Spider, active since 2022, has infiltrated over 100 businesses and extorted more than $100 million globally. ([cyberscoop.com](https://cyberscoop.com/scattered-spider-peter-stokes-cybercrime-extradition/?utm_source=openai)) This incident underscores the persistent threat posed by cybercriminal groups employing sophisticated social engineering tactics to infiltrate organizations. The arrest highlights the importance of robust cybersecurity measures and international cooperation in combating cybercrime.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Black Basta Ransomware Group: A Comprehensive Analysis of Its Rise and Fall
Impact· CRITICAL

Black Basta Ransomware Group: A Comprehensive Analysis of Its Rise and Fall

Black Basta, a ransomware-as-a-service (RaaS) group, emerged in April 2022 and rapidly became a significant threat by employing double extortion tactics—encrypting victims' data and exfiltrating sensitive information to pressure organizations into paying ransoms. The group targeted over 500 organizations worldwide across various critical infrastructure sectors, including healthcare, finance, and manufacturing. Their operations involved sophisticated social engineering techniques, exploitation of known vulnerabilities, and partnerships with malware distributors like QakBot to gain initial access. In 2025, internal conflicts and law enforcement actions led to a decline in Black Basta's activities, culminating in the group's shutdown. ([techrepublic.com](https://www.techrepublic.com/article/black-basta-ransomware-attack/?utm_source=openai)) The Black Basta case underscores the evolving nature of ransomware threats, highlighting the importance of robust cybersecurity measures and proactive threat intelligence to defend against sophisticated cybercriminal operations. The group's rapid rise and eventual downfall illustrate the dynamic landscape of cyber threats and the necessity for organizations to remain vigilant and adaptable.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
NAIC's 2026 Data Breach: A ShinyHunters Exploit of Oracle PeopleSoft
Impact· CRITICAL

NAIC's 2026 Data Breach: A ShinyHunters Exploit of Oracle PeopleSoft

In June 2026, the National Association of Insurance Commissioners (NAIC) experienced a cyberattack by the ShinyHunters group, who exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft servers. The attackers claimed to have stolen 3.1 TB of data, including insurer regulatory filings and AWS infrastructure configurations. NAIC's investigation indicated that only publicly available data, outdated logs, and configuration files were accessed, with no evidence of personal or financial data exposure. The breach led to operational disruptions, such as temporary suspension of data feeds by credit rating agencies and a pause in NAIC's investment designation work. This incident underscores the critical importance of promptly addressing zero-day vulnerabilities and implementing robust security measures to protect sensitive data. Organizations must remain vigilant against sophisticated threat actors like ShinyHunters, who continue to exploit unpatched systems, emphasizing the need for proactive cybersecurity strategies and timely software updates.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Unveiling Mistic: The Stealthy Backdoor Linked to KongTuke
Impact· HIGH

Unveiling Mistic: The Stealthy Backdoor Linked to KongTuke

In April 2026, a new backdoor named Mistic was identified in attacks targeting organizations across the insurance, education, IT, and professional services sectors. Linked to the initial access broker KongTuke, Mistic operates entirely in memory, avoiding disk writes and incorporating a self-deletion feature to evade detection. The malware is deployed through DLL side-loading techniques, utilizing legitimate Microsoft endpoint security tools to blend in with trusted software. Once established, Mistic enables attackers to execute code, manage files, and load additional modules, facilitating long-term, low-visibility access to compromised systems. The emergence of Mistic underscores a growing trend among threat actors to develop and deploy sophisticated, stealthy malware capable of evading traditional security measures. This development highlights the need for organizations to enhance their detection and response capabilities, particularly against fileless malware that operates in memory and leverages legitimate processes to achieve persistence.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Mistic Backdoor: A New Threat in Ransomware Attacks
Impact· HIGH

Mistic Backdoor: A New Threat in Ransomware Attacks

In April 2026, a new backdoor named Mistic was identified in attacks targeting sectors such as insurance, education, IT, and professional services. Linked to the initial access broker KongTuke (also known as Woodgnat), Mistic facilitates unauthorized access to corporate networks, which is then sold to ransomware groups including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. The malware employs DLL side-loading techniques to maintain stealth and persistence, allowing attackers to execute commands, manipulate files, and exfiltrate data without detection. The emergence of Mistic underscores a growing trend where initial access brokers develop sophisticated tools to infiltrate networks, subsequently enabling ransomware operations. This development highlights the critical need for organizations to enhance their cybersecurity measures to detect and prevent such stealthy intrusions.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Xsolis Data Breach 2026: A Wake-Up Call for Healthcare Cybersecurity
Impact· HIGH

Xsolis Data Breach 2026: A Wake-Up Call for Healthcare Cybersecurity

In January 2026, healthcare technology company Xsolis experienced a data breach affecting nearly 1.4 million individuals. The breach resulted from a targeted phishing attack on January 20, 2026, which allowed unauthorized access to Xsolis's network. The attackers accessed files containing sensitive personal and health information, including names, addresses, dates of birth, Social Security numbers, health insurance details, and medical treatment information. Xsolis detected the unauthorized activity on January 22, 2026, promptly contained the breach, and initiated an investigation with external cybersecurity experts. The company has since notified affected individuals and implemented additional security measures to prevent future incidents. This incident underscores the persistent threat of phishing attacks in the healthcare sector, highlighting the critical need for robust cybersecurity measures and employee training to protect sensitive patient data. The breach also raises concerns about potential identity theft and fraud for the affected individuals, emphasizing the importance of vigilance and proactive monitoring of personal information.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
SIM Swap Attack Highlights Need for Enhanced Authentication Measures
Impact· HIGH

SIM Swap Attack Highlights Need for Enhanced Authentication Measures

In June 2026, Torsten George, a chief cybersecurity evangelist, experienced a SIM swap attack that led to an attempted account takeover. The attacker, posing as an AT&T representative, had previously conducted a SIM swap, allowing them to intercept one-time passwords (OTPs) sent via text. During a subsequent call, the attacker sought additional credentials to gain full access to George's AT&T account. Recognizing the threat, George acted swiftly to regain control, preventing unauthorized access. This incident underscores the vulnerabilities associated with SMS-based OTPs and highlights the need for multi-layered security measures. The resurgence of SIM swap attacks, as demonstrated in this case, emphasizes the importance of adopting more secure authentication methods, such as app-based OTPs or hardware tokens, to mitigate the risks of account takeovers.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Texas Parks and Wildlife Department Data Breach Exposes Over 3 Million Records
Impact· HIGH

Texas Parks and Wildlife Department Data Breach Exposes Over 3 Million Records

In June 2026, the Texas Parks and Wildlife Department (TPWD) disclosed a significant data breach involving its license system vendor, exposing personal information of over 3 million individuals. The compromised data includes driver's license information, passport numbers, email addresses, phone numbers, and residential addresses. Notably, Social Security numbers, dates of birth, and financial information were not affected. The breach was detected by the Texas Cyber Command, prompting an immediate investigation and the implementation of enhanced security measures. ([tpwd.texas.gov](https://tpwd.texas.gov/about/notification-of-data-security-incident/?utm_source=openai)) This incident underscores the escalating risks associated with third-party vendors in data security. Organizations are increasingly vulnerable to breaches through external partners, highlighting the necessity for stringent vendor management and comprehensive security protocols to safeguard sensitive information.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
DentaQuest Data Breach 2026: ShinyHunters Expose 2.6 Million Records
Impact· HIGH

DentaQuest Data Breach 2026: ShinyHunters Expose 2.6 Million Records

In May 2026, DentaQuest, a leading dental benefits administrator in the United States, experienced a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers infiltrated DentaQuest's network, exfiltrating over 234 GB of sensitive data, which included personal information of approximately 2.6 million individuals. The compromised data encompassed email addresses, full names, phone numbers, government-issued IDs, health insurance details, genders, and dates of birth. Following unsuccessful ransom negotiations, ShinyHunters publicly released the stolen data, amplifying the potential for identity theft and fraud among affected individuals. This incident underscores a troubling trend of cyber extortion targeting healthcare organizations, highlighting the critical need for robust cybersecurity measures and rapid incident response protocols to protect sensitive patient information.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports