Insurance firm Johnson & Johnson disclosed August 2024 breach affecting 3,200
- Organization
- Johnson & Johnson, Inc. (insurance firm)
- Exploit
- Hacking
- Industry
- Insurance
Johnson & Johnson, Inc., an insurance firm based in Mount Pleasant, South Carolina, disclosed a network intrusion in October 2024. The company has no connection to the pharmaceutical manufacturer of the same name.
According to its notification, suspicious activity on the company's network was detected in mid-August 2024, with the unauthorized access dated on or around August 16. A third-party digital forensics firm was engaged, and the investigation concluded that files relating to the company's insurance practice had been accessed.
More than 3,200 people were affected. The company did not publicly specify which categories of personal information were involved, although individual notification letters listed the elements relevant to each recipient. SecurityWeek noted that no ransomware group had claimed responsibility for the intrusion.
Notification letters began going out on October 18, 2024, and the incident was reported to the Office of the Maine Attorney General. Johnson & Johnson offered affected individuals 12 months of complimentary credit monitoring and identity restoration services, and said it had strengthened its security following the incident. The company stated that it had no evidence at the time that any personal information had been misused.