The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Insurance
Breach intelligence, attack campaigns, and threat reports targeting the Insurance sector.
Explore Other Sectors
Insurance Threat Reports
Critical Bluetooth Vulnerability in Acrisure's KARR Security Systems Exposes Millions of Vehicles
In July 2026, researchers from the University of California, San Diego, identified a critical vulnerability in the KARR Security System, an aftermarket vehicle alarm installed in approximately 2.2 million vehicles across brands like Honda, Toyota, Mazda, Ford, and Jeep. The flaw stemmed from the use of a universal Bluetooth authentication key across all devices, allowing attackers within Bluetooth range to remotely unlock doors, control vehicle functions, and disable engine startup. This vulnerability affected vehicles sold since 2017, many of which had the system installed without owners' active knowledge or subscription. ([malwarebytes.com](https://www.malwarebytes.com/blog/bugs/2026/07/millions-of-cars-could-be-tracked-and-unlocked-by-a-hidden-security-flaw?utm_source=openai)) The incident underscores the growing risks associated with aftermarket automotive security systems, especially those installed by dealerships without stringent security protocols. As vehicles become increasingly connected, the potential attack surface expands, necessitating robust security measures and prompt vulnerability disclosures to protect consumers from unauthorized access and potential theft.
1 month ago
Kill Chain
Critical Bluetooth Vulnerability in KARR Security System Affects Millions of Vehicles
In July 2026, researchers at the University of California, San Diego, identified a critical Bluetooth vulnerability in the KARR Security System, an aftermarket car alarm installed in over 2.2 million vehicles across the United States. This flaw allows attackers within Bluetooth range to unlock doors, disable alarms, control vehicle lights and horns, and even prevent engine startup, all without the owner's knowledge. The vulnerability stems from the use of a universal authentication key stored in plain text within the system's mobile application, making all installed units susceptible to remote exploitation. This incident underscores the growing security risks associated with aftermarket automotive devices, especially those utilizing wireless communication protocols like Bluetooth. As vehicles become increasingly connected, the potential attack surface expands, highlighting the urgent need for robust security measures and regular vulnerability assessments in automotive systems to protect consumers from emerging cyber threats.
1 month ago
Kill Chain
Ghanaian National Sentenced for $10M Romance Scam
In July 2026, Derrick Van Yeboah, a 41-year-old Ghanaian national, was sentenced to 85 months in prison for orchestrating romance scams that defrauded victims of over $10 million. Operating from February 2015 to October 2024, Van Yeboah impersonated romantic partners online, targeting primarily older and vulnerable individuals. He was a high-ranking member of a Ghana-based criminal organization responsible for stealing more than $100 million through romance scams and business email compromises. This case underscores the persistent threat of online romance scams, which exploit individuals' trust and emotional vulnerabilities. The substantial financial losses and emotional devastation experienced by victims highlight the need for increased awareness and vigilance in online interactions.
1 month ago
Kill Chain
MCBS Data Breach 2025: A Wake-Up Call for Healthcare Cybersecurity
In September 2025, Medical Computer Business Services (MCBS), a healthcare billing firm based in Augusta, Georgia, experienced a significant data breach. Unauthorized access to their network occurred between September 22 and 26, 2025, leading to the exposure of sensitive information belonging to 1,261,464 individuals. The compromised data included names, addresses, Social Security numbers, dates of birth, health insurance details, and medical histories. The PEAR ransomware group claimed responsibility for the attack, alleging the exfiltration of 3.3 terabytes of data from MCBS systems. This incident underscores the escalating threat posed by ransomware groups targeting the healthcare sector. The breach highlights the critical need for robust cybersecurity measures to protect sensitive patient information and the importance of timely detection and response to such intrusions.
1 month ago
Kill Chain
CTM360 Exposes Real-Time Account Hijacking in Evolving Insurance Phishing Attacks
In July 2026, CTM360 uncovered a sophisticated phishing campaign targeting insurance providers across multiple regions, including Saudi Arabia, Europe, the United States, and India. Unlike traditional methods that collect credentials for later use, attackers now synchronize their activities with victims in real time. By leveraging sponsored Google advertisements, victims searching for insurance services are redirected to fraudulent websites that closely mimic legitimate insurance portals. As victims enter their login credentials, attackers simultaneously authenticate against the actual insurance portals, enabling immediate account hijacking within a single browsing session. This evolution in phishing tactics underscores a significant shift in cybercriminal strategies, emphasizing the need for organizations to enhance their detection and response mechanisms. The use of real-time credential exploitation and legitimate advertising platforms for phishing delivery highlights the increasing sophistication of threat actors and the urgency for proactive cybersecurity measures.
2 months ago
Kill Chain
European Banks' Data Exposure Through Tracking Pixels
In July 2026, research revealed that several European financial institutions inadvertently transmitted sensitive customer data to third-party advertising and analytics platforms via tracking pixels embedded in their websites. This data leakage occurred even before users provided consent, and in some cases, continued despite users rejecting tracking technologies. The exposed information included personally identifiable details such as email addresses, phone numbers, and financial data, raising significant compliance, security, and privacy concerns. This incident underscores the critical need for organizations to rigorously monitor and control third-party code execution on their platforms. The misuse of tracking technologies without proper consent not only violates data protection regulations like GDPR but also erodes customer trust. Financial institutions must implement robust runtime controls and ensure that consent mechanisms are effectively enforced to prevent unauthorized data sharing.
2 months ago
Kill Chain
Cybercriminals' Quest for 'Clean' Residential Proxies in Carding Schemes
In July 2026, Flare researchers analyzed 2,889 underground posts across 545 threads, revealing that cybercriminals are increasingly seeking 'clean' residential proxies to enhance their carding operations. These proxies are now part of a broader identity-simulation stack, including device fingerprints, browser profiles, and transaction behaviors, to evade detection by financial institutions. The study highlights a shift where residential IPs alone are insufficient, leading to a secondary market for proxies with pristine histories. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/inside-the-search-for-clean-residential-proxies-for-carding/?utm_source=openai)) This trend underscores the evolving tactics of cybercriminals who are investing more effort into creating convincing digital identities. The demand for 'clean' proxies indicates that traditional IP-based trust models are becoming less reliable, necessitating more comprehensive security measures. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/inside-the-search-for-clean-residential-proxies-for-carding/?utm_source=openai))
2 months ago
Kill Chain
23andMe Data Breach: A Wake-Up Call for Credential Security
In October 2023, genetic testing company 23andMe disclosed a significant data breach resulting from credential-stuffing attacks that went undetected for five months, from April to September 2023. Attackers exploited reused passwords to access approximately 14,000 user accounts, subsequently exposing sensitive genetic and personal information of 6.9 million customers. This data was later found for sale on the dark web, raising serious privacy concerns. The incident underscores the critical importance of robust cybersecurity measures, including the implementation of multi-factor authentication and proactive monitoring systems. Organizations handling sensitive data must prioritize these defenses to prevent similar breaches and protect consumer trust.
2 months ago
Kill Chain
Unimed Cyberattack 2026: A Wake-Up Call for Healthcare Vendor Security
In April 2026, Unimed, a German medical billing provider servicing numerous university hospitals, suffered a cyberattack resulting in the theft of over 72,000 patient records. The breach exposed sensitive information, including names, addresses, and health data. Unimed promptly reported the incident to authorities and collaborated with affected hospitals to notify impacted patients. The attack did not compromise the IT systems of the client hospitals, ensuring that patient care remained unaffected. ([luxgap.com](https://luxgap.com/articles/unimed-72000-patients-voles-dlp-article-32-transferts-rgpd?lang=en&utm_source=openai)) This incident underscores the critical vulnerabilities within third-party service providers in the healthcare sector. As cybercriminals increasingly target supply chains, healthcare organizations must reassess and fortify their vendor risk management and data protection strategies to prevent similar breaches.
2 months ago
Kill Chain
Scattered Spider Member Peter Stokes Extradited to US in 2026
In July 2026, Peter Stokes, a 19-year-old dual U.S.-Estonian citizen and alleged member of the cybercriminal group Scattered Spider, was extradited to the United States following his arrest in Finland. Stokes is accused of participating in multiple data theft and extortion attempts, including attacks on a luxury jewelry retailer in May 2025 and a U.S.-based insurance company in June 2025. Scattered Spider, active since 2022, has infiltrated over 100 businesses and extorted more than $100 million globally. ([cyberscoop.com](https://cyberscoop.com/scattered-spider-peter-stokes-cybercrime-extradition/?utm_source=openai)) This incident underscores the persistent threat posed by cybercriminal groups employing sophisticated social engineering tactics to infiltrate organizations. The arrest highlights the importance of robust cybersecurity measures and international cooperation in combating cybercrime.
2 months ago
Kill Chain
Black Basta Ransomware Group: A Comprehensive Analysis of Its Rise and Fall
Black Basta, a ransomware-as-a-service (RaaS) group, emerged in April 2022 and rapidly became a significant threat by employing double extortion tactics—encrypting victims' data and exfiltrating sensitive information to pressure organizations into paying ransoms. The group targeted over 500 organizations worldwide across various critical infrastructure sectors, including healthcare, finance, and manufacturing. Their operations involved sophisticated social engineering techniques, exploitation of known vulnerabilities, and partnerships with malware distributors like QakBot to gain initial access. In 2025, internal conflicts and law enforcement actions led to a decline in Black Basta's activities, culminating in the group's shutdown. ([techrepublic.com](https://www.techrepublic.com/article/black-basta-ransomware-attack/?utm_source=openai)) The Black Basta case underscores the evolving nature of ransomware threats, highlighting the importance of robust cybersecurity measures and proactive threat intelligence to defend against sophisticated cybercriminal operations. The group's rapid rise and eventual downfall illustrate the dynamic landscape of cyber threats and the necessity for organizations to remain vigilant and adaptable.
2 months ago
Kill Chain
NAIC's 2026 Data Breach: A ShinyHunters Exploit of Oracle PeopleSoft
In June 2026, the National Association of Insurance Commissioners (NAIC) experienced a cyberattack by the ShinyHunters group, who exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft servers. The attackers claimed to have stolen 3.1 TB of data, including insurer regulatory filings and AWS infrastructure configurations. NAIC's investigation indicated that only publicly available data, outdated logs, and configuration files were accessed, with no evidence of personal or financial data exposure. The breach led to operational disruptions, such as temporary suspension of data feeds by credit rating agencies and a pause in NAIC's investment designation work. This incident underscores the critical importance of promptly addressing zero-day vulnerabilities and implementing robust security measures to protect sensitive data. Organizations must remain vigilant against sophisticated threat actors like ShinyHunters, who continue to exploit unpatched systems, emphasizing the need for proactive cybersecurity strategies and timely software updates.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports