Landmark Admin breach exposed data of more than 800,000 insurance customers
- Organization
- Landmark Admin, LLC
- Exploit
- Ransomware
- Industry
- Insurance Services
Landmark Admin, a Texas company that provides policy administration services to life insurance and annuity carriers, said a 2024 network intrusion exposed the personal information of 806,519 people, including about 68,000 Texas residents.
Landmark detected suspicious activity on May 13, 2024, disconnected the affected systems, blocked remote access to its network and engaged an outside cybersecurity firm. While that investigation was still running, the intruder regained access to the environment on June 17. The forensic review concluded around July 24, 2024 and found that data had been both encrypted and copied out of the network.
The exposed information varied by person and could include names, addresses, Social Security numbers, tax identification numbers, driver's license or state identification numbers, passport numbers, dates of birth, financial account and routing numbers, medical information, health insurance policy numbers and life insurance or annuity policy details.
Policyholders of several Liberty Bankers Insurance Group carriers were caught up in the breach, among them American Monumental Life, Pellerin Life, American Benefit Life, Liberty Bankers Life, Continental Mutual and Capitol Life. The first notification letters went out on October 23 and 24, 2024, and Landmark offered a year of complimentary credit monitoring. The company said it had since added data encryption and further network security controls.
Updates
-
Landmark Admin revised the number of affected people to 1,613,773 in a supplemental filing with the Maine Attorney General, double the 806,519 it reported in October 2024.