Ransomware
BleepingComputer
Primary Source βIncident Details
Landmark Admin LLC, a Texas-based third-party administrator for multiple insurance companies, detected unauthorized access to its systems on May 13, 2024, and was breached again on June 17 while the investigation was still underway. The breach involved ransomware and data exfiltration via stolen VPN credentials. The final count reached 1.6 million affected individuals, with personal data including names, addresses, dates of birth, driver’s license numbers, government/passport IDs, Social Security numbers, medical and health insurance information, and financial information. Downstream insurance carrier clients include American Benefit Life Insurance, Liberty Bankers Life Insurance, and others. A $6 million class action settlement was reached.
Technical Details
- Initial Attack Vector
- CWE-522: Insufficiently Protected Credentials (stolen VPN credentials)
- Vendor / Product
- Landmark Admin insurance administration platform
Timeline
- 2024-05-13 Breach occurred
- 2024-10-01 Publicly disclosed
- 2024-10-01 Customers notified