Insurance — Cyber Threat Activity
Insurance holds no recorded incidents in our log and a deliberately thin actor graph of 5 groups, including Medusa, RomCom, Silent Ransom Group, Agrius and RedCurl, with 9 malware families linked through those actors. That sparseness understates a sector that became a named target in 2025, when incident responders reported social-engineering crews moving through US insurance carriers in a concentrated run before pivoting to retail, using help-desk impersonation to reset credentials and multi-factor enrolment rather than exploiting software. Insurers are attractive for reasons that compound. They hold medical histories, financial positions, claims investigations and personal data on entire policyholder populations, which makes them a data target on the scale of a health system. They hold underwriting and actuarial models that are the firm's competitive product. Cyber insurers in particular hold their clients' security assessments, incident histories and coverage limits, which is intelligence about which of those clients can pay a ransom and how much, and that makes a cyber underwriter a target-selection database for anyone who reaches it. The sector also sits behind a broad intermediary layer of brokers, claims adjusters, third-party administrators and managed repair networks, each holding policyholder data with weaker controls than the carrier. Read the empty incident count as a collection artefact rather than a finding: insurers disclose to regulators and policyholders rather than appearing on leak sites, and the actor associations shown come from published research rather than incidents we have attributed ourselves.
- Recorded incidents: 32
- Incidents, trailing 180 days: 10
- Tracked threat actors: 15
- Malware families: 17
Recent incidents
- American Plan Administrators 2026-08-29
- CUI Agency 2026-07-01
- Anadolu Anonim Türk Sigorta Şirketi 2026-06-16
- DentaQuest 2026-05-23
- grupo55.com 2026-05-17
- Pequod Associates 2026-05-12
- Canada Life 2026-04-20
- Kemper 2026-04-15
- Surplus Line Association of California 2026-04-04
- shlomo bit 2026-03-11
- North Star Insurance Advisors 2026-03-05
- McFarlane Agencies 2026-02-20
- Mutest 2026-01-21
- Aarco 2025-11-19
- LV.COM 2025-11-07
- Brownstone Agency 2025-09-12
- SWAN, Mauritius 2025-08-25
- Allianz Life 2025-07-16
- TJ Assurance Partners PAC 2025-03-12
- JPWEST.COM 2025-02-27
Threat actors targeting Insurance
- Cl0p 4 incidents
- Akira 3 incidents
- KillSec 2 incidents
- Qilin 2 incidents
- Medusa Ransomware 1 incident
- Genesis 1 incident
- INC Ransom 1 incident
- LockBit 1 incident
- M3rx 1 incident
- RansomHub 1 incident
- The Gentlemen 1 incident
- RomCom researched targeting
- Silent Ransom Group researched targeting
- Agrius researched targeting
- RedCurl researched targeting
Where these victims are
- United States 11
- Mexico 2
- Singapore 2
- Canada 1
- Denmark 1
- France 1
- Israel 1
- Japan 1
- Mauritius 1
- Morocco 1
- Spain 1
- Turkey 1
Malware used against Insurance
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Cobalt Strike Malware
- Impacket Tool
- Mimikatz Tool
- PsExec Tool
- Medusa Ransomware Malware
- NetSupport Manager Tool
- Rclone Tool
- SystemBC Malware
- Apostle Malware
- ASPXSpy Malware
- BFG Agonizer Malware
- certutil Tool
Coverage. 95.5% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.