The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Insurance
Breach intelligence, attack campaigns, and threat reports targeting the Insurance sector.
Explore Other Sectors
Insurance Threat Reports
Lawmakers Propose Tougher Penalties for Hospital Ransomware Attacks
In April 2026, during a House Homeland Security Committee hearing, lawmakers discussed intensifying penalties for ransomware attacks targeting hospitals. Proposals included classifying such attacks as acts of terrorism and pursuing homicide charges when patient deaths result. These discussions were prompted by a significant rise in healthcare ransomware incidents, which doubled from 238 in 2024 to 460 in 2025, making the healthcare sector the most targeted industry. The hearing highlighted the severe operational disruptions and potential loss of life caused by these cyberattacks, emphasizing the need for stronger deterrents and legal frameworks to address the escalating threat. This incident underscores the growing urgency to enhance cybersecurity measures within the healthcare sector. The increasing frequency and severity of ransomware attacks necessitate immediate action to protect critical infrastructure and patient safety. Legislative initiatives aiming to reclassify these cybercrimes reflect a broader recognition of their potential to cause significant harm, signaling a shift towards more aggressive legal responses to deter future attacks.
5 months ago
Kill Chain
Germany Unmasks Leader of REvil and GandCrab Ransomware Groups
In April 2026, German authorities identified 31-year-old Russian national Daniil Maksimovich Shchukin as 'UNKN,' the alleged leader of the notorious ransomware groups GandCrab and REvil. Between 2019 and 2021, Shchukin and his associate, 43-year-old Anatoly Sergeevitsch Kravchuk, reportedly executed at least 130 cyberattacks in Germany, extorting nearly €2 million and causing over €35 million in economic damages. These groups pioneered the double extortion tactic, demanding ransom for decrypting systems and additional payment to prevent data leaks. This revelation underscores the persistent threat posed by sophisticated ransomware operations and highlights the importance of international collaboration in combating cybercrime. Organizations must remain vigilant, as the identification of such key figures does not eliminate the risk of future attacks employing similar tactics.
5 months ago
Kill Chain
Cybercriminals Exploit Vacant Homes to Intercept Mail and Commit Fraud
In April 2026, cybersecurity analysts uncovered a sophisticated fraud scheme where adversaries exploit vacant residential properties to intercept sensitive mail, facilitating identity theft and financial fraud. Attackers identify unoccupied homes through real estate listings, register for postal services like Informed Delivery to monitor incoming mail, and use change-of-address requests to redirect mail to addresses under their control. This method combines open-source intelligence, legitimate postal services, and fake identities to gain persistent access to victims' correspondence. This incident highlights a growing trend where cybercriminals blend digital tactics with physical-world manipulation, exploiting legitimate services to bypass traditional cybersecurity defenses. The rise in such hybrid cybercrime underscores the need for enhanced vigilance and cross-domain monitoring to detect and prevent these evolving threats.
5 months ago
Kill Chain
Cognizant TriZetto 2024 Data Breach: A Wake-Up Call for Healthcare Cybersecurity
In November 2024, TriZetto Provider Solutions, a subsidiary of Cognizant, experienced a significant data breach that went undetected until October 2, 2025. During this period, unauthorized actors accessed sensitive information of over 3.4 million individuals, including names, addresses, dates of birth, Social Security numbers, and health insurance details. The breach was identified when suspicious activity was detected on a web portal used by healthcare providers to verify patient insurance eligibility. ([techcrunch.com](https://techcrunch.com/2026/03/06/trizetto-confirms-3-4m-peoples-health-and-personal-data-was-stolen-during-breach/?utm_source=openai)) This incident underscores the critical need for robust cybersecurity measures and timely detection mechanisms within the healthcare sector. The prolonged undetected access highlights vulnerabilities that can lead to substantial data exposure, emphasizing the importance of continuous monitoring and rapid response strategies to protect sensitive patient information.
6 months ago
Kill Chain
Deepfake Injection Attacks: A Growing Threat to Identity Verification in 2025
In 2025, the financial sector faced a significant surge in deepfake and injection attacks targeting identity verification processes. Fraudsters utilized AI-generated media to impersonate individuals during onboarding and authentication, leading to unauthorized access and substantial financial losses. Notably, a multinational firm in Singapore was nearly defrauded of $500,000 when attackers used deepfake video avatars to impersonate company executives during a Zoom call. ([regulaforensics.com](https://regulaforensics.com/blog/identity-verification-incidents-2025/?utm_source=openai)) This incident underscores the escalating threat posed by deepfake technologies in compromising identity verification systems. The increasing sophistication and accessibility of AI tools have enabled attackers to bypass traditional security measures, highlighting the urgent need for enhanced detection and prevention strategies.
6 months ago
Kill Chain
Recorded Future and CYBERA Join Forces to Tackle Escalating Money Mule Fraud
In February 2026, Recorded Future announced an expansion of its payment fraud prevention capabilities through a partnership with CYBERA, a leader in detecting and verifying data on scam-linked bank accounts. This collaboration introduces Money Mule Intelligence, a tool designed to help fraud teams identify accounts used by criminals to extract and move stolen funds. The initiative addresses the escalating threat of Authorized Push Payment (APP) fraud, which is projected to reach nearly $15 billion in the U.S. by 2028, up from $8.3 billion in 2024. The rise in APP fraud is driven by factors such as AI-generated deepfakes, personalized scam scripts, and instant payment systems that outpace traditional fraud controls. Money mule accounts serve as critical infrastructure for these scams, enabling the conversion of stolen payments into untraceable cash or cryptocurrency. The sophistication of mule operations has increased, with criminals employing 'mule herders' who manage numerous accounts and use AI to simulate normal transaction behavior, making detection challenging. Regulators are responding by shifting liability to banks, emphasizing the need for proactive detection and disruption of mule accounts to prevent fraud and comply with emerging reimbursement requirements.
7 months ago
Kill Chain
Understanding TOAD Attacks: Bypassing Email Security Through Social Engineering
In early 2025, cybercriminals escalated the use of Telephone-Oriented Attack Delivery (TOAD) techniques to bypass traditional email security measures. These attacks involve sending emails that appear to be from legitimate services, such as Microsoft Entra, Zoom, or Hulu+, containing fake invoices or alerts with a phone number for recipients to call. Upon calling, victims are connected to fraudulent call centers where they are manipulated into downloading remote access software, granting attackers control over their systems. This method effectively circumvents email filters by excluding malicious links or attachments, relying instead on social engineering tactics to exploit human trust. ([cybernews.com](https://cybernews.com/security/new-toad-phishing-campaign-targets-microsoft-entra-invitees-with-fake-invoices/?utm_source=openai)) The prevalence of TOAD attacks underscores a significant shift in phishing strategies, emphasizing the need for organizations to enhance their security awareness training and adopt multi-layered defense mechanisms. As these attacks exploit trusted communication channels and human psychology, traditional technical defenses alone are insufficient, highlighting the urgency for comprehensive security approaches that address both technological and human factors. ([phishcloud.com](https://phishcloud.com/toad-phishing-attack-prevention/?utm_source=openai))
7 months ago
Kill Chain
UAC-0050's Expansion: European Financial Institution Targeted with RMS Malware
In February 2026, the Russia-aligned threat actor UAC-0050, also known as Mercenary Akula, targeted a European financial institution involved in regional development and reconstruction initiatives. The attack began with a spear-phishing email that spoofed a Ukrainian judicial domain, directing the recipient—a senior legal and policy advisor—to download a malicious archive file. This file initiated a multi-layered infection chain, ultimately deploying the Remote Manipulator System (RMS), a legitimate remote desktop software, granting the attackers persistent and stealthy access to the victim's system. This incident underscores a significant shift in UAC-0050's operations, expanding their focus beyond Ukraine to entities supporting the nation. The use of legitimate remote access tools like RMS highlights the evolving tactics of threat actors to evade detection. Organizations, especially those involved in sensitive geopolitical areas, must remain vigilant against such sophisticated social engineering attacks.
7 months ago
Kill Chain
CEO Deepfake Scam 2019: A Wake-Up Call for Corporate Security
In March 2019, a UK-based energy firm's CEO was deceived by a deepfake audio impersonation of his German parent company's chief executive. The fraudster, using AI-generated voice technology, instructed the CEO to transfer €220,000 (approximately $243,000) to a Hungarian supplier's account. Believing the request was legitimate, the CEO complied. Subsequent attempts for additional transfers raised suspicions, leading to the discovery of the scam. The initial funds were moved from Hungary to Mexico and then dispersed to other locations, making recovery challenging. ([forbes.com](https://www.forbes.com/sites/jessedamiani/2019/09/03/a-voice-deepfake-was-used-to-scam-a-ceo-out-of-243000/?utm_source=openai)) This incident underscores the escalating threat of AI-driven deepfake technologies in corporate fraud. As these tools become more sophisticated and accessible, organizations face increased risks of impersonation attacks targeting financial transactions and sensitive information. The event highlights the urgent need for enhanced security measures and employee training to detect and prevent such advanced social engineering tactics.
7 months ago
Kill Chain
Security Flaws in Android Mental Health Apps Put Millions at Risk
In February 2026, security researchers identified significant vulnerabilities in several Android mental health applications, collectively downloaded over 14.7 million times from Google Play. These apps, designed to assist users with conditions such as depression and anxiety, were found to contain a total of 1,575 security flaws, including 54 high-severity and 538 medium-severity issues. Exploiting these vulnerabilities could allow attackers to intercept sensitive user data, including therapy session transcripts and personal health information, thereby compromising user privacy and confidentiality. This incident underscores the critical need for rigorous security measures in applications handling sensitive health data. The discovery highlights the potential risks associated with inadequate app security, emphasizing the importance of regular security assessments and compliance with data protection regulations to safeguard user information.
7 months ago
Kill Chain
PayPal's 2025 Data Breach: A Cautionary Tale in Financial Data Security
In 2025, PayPal experienced a significant data breach due to a code change in its Working Capital application, which inadvertently exposed sensitive customer information, including Social Security numbers and dates of birth, for nearly six months. The breach was discovered on December 12, 2025, but had been active since July 1, 2025. Approximately 100 customers were affected by this incident. ([cybernews.com](https://cybernews.com/security/paypal-six-month-breach-ssn-working-capital-app/?utm_source=openai)) This incident underscores the critical importance of rigorous code review processes and robust access controls in financial applications. The prolonged exposure period highlights the necessity for continuous monitoring and rapid response mechanisms to detect and mitigate unauthorized access to sensitive data.
7 months ago
Kill Chain
Change Healthcare's 2024 Ransomware Attack: A Wake-Up Call for Healthcare Cybersecurity
In February 2024, Change Healthcare, a subsidiary of UnitedHealth Group, suffered a significant ransomware attack orchestrated by the Russian group ALPHV (BlackCat). The attackers exploited a server lacking multifactor authentication, gaining unauthorized access and encrypting critical systems. This breach disrupted essential healthcare operations nationwide, including insurance eligibility verification, prescription processing, and claims management, affecting approximately 190 million individuals. The incident underscored the vulnerabilities in third-party service providers within the healthcare sector, prompting the Department of Health and Human Services to intensify efforts in identifying and mitigating such risks. The attack's magnitude and impact have led to increased regulatory scrutiny and a reevaluation of cybersecurity practices across the industry.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports