Globe Life extorted over data stolen from American Income Life

Organization
Globe Life Inc.
Exploit
Hacking
Industry
Insurance

Globe Life Inc., a Texas-based life and health insurance holding company, disclosed in an October 17, 2024 filing with the Securities and Exchange Commission that an unidentified threat actor was demanding payment in exchange for not publishing customer data taken from its subsidiary American Income Life Insurance Company.

The company said the records identified so far covered more than 5,000 people and could include names, email addresses, telephone numbers, postal addresses, dates of birth, Social Security numbers, health-related information and insurance policy details. Globe Life said no credit card or banking information appeared to be involved, and that the full scope of what the attacker held had not been verified.

Rather than pay, Globe Life reported the matter to federal law enforcement and engaged outside counsel and cybersecurity specialists. The attacker escalated by passing information on a limited number of individuals to short sellers and to plaintiffs' attorneys, an unusual pressure tactic aimed at the company's share price and its legal exposure. No ransomware was deployed and the company reported no operational disruption.

The disclosure followed a June 2024 filing in which Globe Life told the SEC that a state insurance regulator had asked about potential weaknesses in access permissions and user identity management for a company web portal. In an amended filing on January 30, 2025, Globe Life said it had begun notifying roughly 850,000 people whose information was stored in the databases the attacker targeted, and offering them credit monitoring.

Sources