The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Insurance
Breach intelligence, attack campaigns, and threat reports targeting the Insurance sector.
Explore Other Sectors
Insurance Threat Reports
Operation DoppelBrand: Unveiling GS7's Credential Harvesting Tactics
Between December 2025 and January 2026, the GS7 cyberthreat group executed Operation DoppelBrand, a sophisticated phishing campaign targeting Fortune 500 companies, primarily in the financial sector. By creating near-identical replicas of corporate login portals, GS7 successfully harvested employee credentials, enabling unauthorized remote access to sensitive systems. The group registered over 150 malicious domains, utilizing services like NameCheap and Cloudflare to obscure their infrastructure, and exfiltrated stolen data via Telegram bots. This campaign underscores the evolving tactics of cybercriminals in credential harvesting and the critical need for robust cybersecurity measures. The incident highlights the increasing prevalence of brand impersonation in phishing attacks, emphasizing the necessity for organizations to implement advanced detection mechanisms and employee training to mitigate such threats.
7 months ago
Kill Chain
Europol Arrests 34 Black Axe Members in Massive 2026 Organized Cyber-Fraud Takedown
In January 2026, Europol and Spanish authorities arrested 34 suspected members of the Black Axe organized crime syndicate in Spain, dismantling a major transnational cyber-fraud operation. The group, originating from Nigeria but operating internationally, orchestrated a series of sophisticated cyber-enabled crimes, including business email compromise, romance and inheritance scams, credit card and tax fraud, and extensive money laundering. Law enforcement seized over €185,000 ($216,000) in assets and disrupted fraud estimated at more than €5.9 million ($6.9M), highlighting Black Axe's role in global financial crime and cyber-enabled offenses. This incident underscores the growing intersection of traditional organized crime with advanced cyber-fraud tactics, as law enforcement faces increasingly complex, multi-jurisdictional threats. The reliance on cyber-enabled fraud techniques by such syndicates reflects an urgent need for organizations to adapt their security posture to address sophisticated, persistent, and highly organized threats.
8 months ago
Kill Chain
Illinois DHS Exposes 700,000+ Residents in Years-long Data Misconfiguration
In September 2025, the Illinois Department of Human Services (IDHS) discovered a data exposure incident affecting nearly 700,000 residents, when maps containing sensitive information were found to be publicly accessible due to misconfigured privacy settings on a mapping website. The breach, which lasted for several years, involved the exposure of addresses, case numbers, demographic details, and medical assistance plan information for Medicaid and Medicare recipients (without names), as well as additional data including names for a smaller group of rehabilitation services clients. Upon discovery, IDHS promptly secured the exposed maps, reviewed affected materials, and implemented safeguards to prevent recurrence. This incident highlights the persistent risk of misconfiguration-based data exposures in public sector organizations, especially with increasing reliance on digital tools for data visualization and resource management. As regulatory scrutiny and public concern over privacy intensify, organizations must prioritize robust controls over platforms managing sensitive information.
8 months ago
Kill Chain
Ransomware at Sedgwick Government Solutions: What the 2026 TridentLocker Breach Reveals
In January 2026, Sedgwick confirmed a security incident at its subsidiary, Sedgwick Government Solutions, a contractor serving over 20 U.S. federal agencies including CISA, DHS, and the U.S. Coast Guard. The breach was perpetrated by the TridentLocker ransomware group, which claimed to have stolen 3.39 GB of sensitive documents and subsequently leaked data on its Tor site. The attackers gained access via an isolated file transfer system; however, Sedgwick asserts no evidence of compromise to core claims servers or operational disruption. External cybersecurity experts and law enforcement were immediately engaged, and affected systems were properly segmented from the wider parent company network. This incident highlights the increased targeting of government contractors by ransomware operators and underscores the importance of network segmentation, prompt incident response, and continuous monitoring. The breach reflects growing regulatory and client demands for transparent reporting and robust data protection as ransomware groups escalate their tactics.
8 months ago
Kill Chain
478,000 Patients Impacted: Covenant Health Suffers Major Qilin Ransomware Breach in 2025
In May 2025, Covenant Health, a prominent Catholic healthcare provider in New England and Pennsylvania, experienced a significant ransomware attack by the Qilin group. The attackers breached the organization's systems on May 18, exfiltrated approximately 852GB of sensitive data—including names, addresses, social security numbers, medical records, and health insurance information—and subsequently encrypted essential files. Discovery of the breach occurred on May 26, with the scale initially underestimated, before forensic analysis revealed that nearly 478,000 patients were affected. The organization launched a comprehensive investigation, secured its systems, and is offering 12 months of free identity protection to impacted individuals. This breach highlights the continued targeting of healthcare organizations by sophisticated ransomware groups seeking to exploit large troves of sensitive personal and medical data. With ransomware tactics evolving and threat actors increasingly publishing stolen data for extortion, robust data protection and incident response have become critical priorities for healthcare providers.
8 months ago
Kill Chain
Ukrainian Ransomware Operator Pleads Guilty in Global Nefilim Extortion Case
Between 2018 and 2021, Artem Aleksandrovych Stryzhak, a Ukrainian national, orchestrated a series of targeted ransomware attacks against high-revenue organizations in the United States and Europe using the Nefilim ransomware strain. The attacks involved gaining unauthorized access to victim networks, exfiltrating sensitive data, and deploying custom ransomware executables, each with unique ransom notes and decryption keys. Victims included companies across multiple sectors such as engineering, aviation, chemicals, insurance, construction, and energy. Stryzhak, arrested in Spain in June 2024 and extradited to the U.S., pleaded guilty to conspiracy to commit fraud and faces up to 10 years in prison. His accomplice, Volodymyr Tymoshchuk, remains at large amid ongoing law enforcement efforts. The incident underscores the operational sophistication of modern ransomware groups, particularly in tailoring attacks to maximize extortion and impact. With financial and reputational damages in the millions, this case highlights the persistent threat of ransomware and the necessity for robust east-west network security, multifactor identity controls, and anomaly detection across the enterprise attack surface.
8 months ago
Kill Chain
How Identity Fraud Among Home-Care Workers Put Patients at Risk in 2025
In late 2025, a series of identity fraud cases within the home healthcare sector exposed substantial patient safety risks, as unqualified individuals impersonated registered caregivers to provide in-home care services. Attackers exploited weak identity and access management processes—primarily by sharing credentials and mobile devices, enabling false geolocation verification—to bypass patient safety protocols. Law enforcement and government reports highlighted multiple cases in the US and UK involving impersonation, altered electronic monitoring, and direct falsification of visit records. These incidents led to financial fraud against Medicaid, diminished quality of patient care, and, in some tragic cases, severe patient neglect or harm. This trend reflects a growing abuse of digital identity controls in healthcare, where rapid sector expansion and understaffed workforces create security gaps. The surge in similar impersonation tactics and the inadequacy of traditional geolocation or password-based controls underline the urgent need for advanced identity verification—such as biometrics—combined with device and contextual authentication, especially as regulatory scrutiny increases.
8 months ago
Kill Chain
European Authorities Dismantle Major Call Center Fraud Ring in Ukraine (2024)
In mid-2024, European law enforcement agencies succeeded in dismantling a major organized fraud ring operating out of Ukraine. This network used illicit call centers to impersonate financial institutions, manipulating victims across Europe—especially in Germany—into divulging sensitive information or making fraudulent investments. Through sophisticated social engineering techniques and well-structured scripts, the group defrauded thousands of individuals of over 10 million euros. The operation also seized electronic equipment and led to at least five arrests. This incident highlights the ongoing evolution of transnational cybercrime syndicates that exploit human vulnerability through social engineering. Call center fraud, often leveraging modern technologies and cross-border coordination, continues to surge even as regulatory and enforcement actions intensify across Europe.
8 months ago
Kill Chain
700Credit 2024 Breach: 5.8 Million Dealership Customers' Data Exposed
In early 2024, 700Credit, a US-based fintech firm specializing in credit and compliance solutions for auto dealerships, disclosed a major data breach affecting over 5.8 million individuals. The breach was traced to a vulnerability in a third-party web application platform, resulting in unauthorized access to sensitive customer data submitted to vehicle dealerships across North America. Exposed data included names, addresses, Social Security Numbers, dates of birth, and driver’s license numbers. The breach forced 700Credit to rapidly contain the issue, engage forensic experts, and notify customers, while drawing regulatory scrutiny due to the significant privacy impact. This incident is especially important as it highlights the persistent risks presented by web application vulnerabilities and supply chain exposure across critical business platforms. Increased attacker focus on third-party dependencies and data-rich payment ecosystems continues to drive urgency around zero trust architectures and more proactive monitoring and response.
8 months ago
Kill Chain
LockBit Ransomware: Why Reputation Now Drives RaaS Attacks and Ransom Payments (2025 Analysis)
In early 2025, research into the LockBit ransomware-as-a-service (RaaS) gang revealed the pivotal role of reputation in both attacker and victim circles. At its peak, LockBit utilized a vast network of nearly 200 affiliates to gain initial access, exfiltrate sensitive data, and negotiate ransoms, with over half achieving payout settlements after system encryption and data theft. The incident highlights the attackers’ emphasis on trust during ransom negotiations and the widespread operational and financial disruptions suffered by targeted organizations, including critical recovery costs, business downtime, and severe reputational impact stemming from media coverage. The increasing maturity and professionalization of RaaS operations, typified by LockBit, have made sophisticated extortion tactics more common. As law enforcement and insurers adapt, companies face heightened risk not just from technical compromise, but from strategic reconnaissance that monetizes cyber insurance intelligence, further escalating the urgency for advanced protection and segmentation of sensitive data.
8 months ago
Kill Chain
FBI: $262M Lost to ATO Fraud as AI Phishing and Holiday Scams Surge in 2025
In late 2025, the FBI reported an alarming uptick in Account Takeover (ATO) fraud totaling over $262 million in losses. Cybercriminals, leveraging advanced AI-driven phishing tactics and holiday-themed scams, targeted individuals, businesses, and financial institutions with convincing impersonations to steal credentials and gain access to banking and sensitive accounts. Upon entry, attackers executed lateral movement, funds transfers, and data exfiltration, impacting organizations of all sizes and sectors by causing substantial financial loss, reputational harm, and regulatory scrutiny. This incident underscores an acceleration in AI-powered social engineering and the increasing sophistication of phishing campaigns, especially during high-activity periods like the holidays. Security teams now face heightened urgency to adapt with advanced detection, identity controls, and zero trust segmentation to address evolving threats using AI and automation.
8 months ago
Kill Chain
Inside the 2025 Digital Fraud Surge: How AI Supercharged Cybercrime
In early 2025, a wave of advanced persistent fraud targeted multiple global organizations as cybercriminals leveraged generative AI and automated bots to launch large-scale digital fraud schemes. Attackers used sophisticated deepfake technology and high-quality counterfeit IDs to penetrate identity verification systems, bypass account controls, and hijack customer accounts across banking, healthcare, and e-commerce sectors. The attacks exploited gaps in east-west traffic security and leveraged encrypted channels to evade detection for months. Businesses suffered significant financial losses, reputational damage, and were forced to bolster their compliance efforts in the wake of the breach. This incident marked a turning point in the evolution of digital fraud, as attackers embraced highly scalable automation and AI for identity-driven campaigns. The surge in industrial-scale fraud highlighted gaps in visibility, zero-trust segmentation, and anomaly detection while placing new urgency on regulatory compliance and modern defense architectures.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports