Insurance giant Globe Life says it’s being extorted by hackers

American insurance giant Globe Life recently confirmed that cybercriminals tried to extort money in exchange for sensitive data they previously stole.

In mid-June 2024, the company reported a cybersecurity incident in which unknown third parties accessed sensitive customer data through one of its web portals.

It has now submitted a new 8-K form with the U.S. Securities and Exchange Commission (SEC), claiming the crooks accessed sensitive data on at least 5,000 customers – although the final number will probably be bigger, once the investigation concludes.

Not a ransomware attack

So far, the analysis has shown the information was taken from a subsidiary called American Income Life Insurance Company, and included personally identifiable information categories such as names, email addresses, phone numbers, postal addresses, and in some instances Social Security numbers, health-related data, and other policy information.

“The threat actor claims to possess additional categories of information, which claims remain under investigation and have not been verified,” the company said in the form, adding credit card and banking information was safe.

The data was not taken as part of a traditional ransomware attack. Globe Life’s systems were not encrypted, and the break-in did not result in the disruption of any services or operations. However, the crooks still tried to trade the data for money:

“Globe Life recently received communications from an unknown threat actor seeking to extort money from the Company in exchange for not disclosing certain information held and used by the Company and its independent agents,” the 8-K form further reads.

It was left unclear if the company paid the demand or not, but it’s most likely that it did not. Instead, Globe Life brought in third-party cybersecurity experts and notified law enforcement.

Affected customers “will notify individuals affected by this incident,” and take steps to protect and remediate the impact for them, it said.

There is currently no evidence that the data was misused.

Via BleepingComputer

Cyber extortion sees huge rise — and small businesses are four times more likely to be hitHere’s a list of the best firewalls todayThese are the best endpoint protection tools right now

Related posts

Intel’s next-gen Arc B580 spotted, backing up rumors of a December launch for Battlemage GPUs

Netflix drops trailer for ‘true-ish’ new series Apple Cider Vinegar that shows the bitter side of the wellness industry

ChatGPT’s Advanced Voice Mode could finally get ‘eyes’ soon with sci-fi video calling feature

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More