Bitsight Recognized as a Visionary in 2026 Gartner® Magic Quadrant™ for Cyber Threat Intelligence Technologies
Get the report and see why Bitsight was named a Visionary.
Insurance has always been a data-rich industry. But recent threat intelligence makes it clear that attackers are not only going after insurers because they are large organizations. They’re going after them because insurance touches some of a threat actor’s favorite things: money, identity, healthcare, legal claims, third-party relationships, and highly sensitive customer records.
Recent Bitsight threat intelligence has surfaced multiple examples of insurance-related data, access, and discussion appearing across criminal forums, ransomware leak sites, and other underground sources. Some of the activity is direct, such as a claimed repost involving a prominent French insurance company’s data and access, allegedly impacting more than 8 million records. Another post advertised a Taiwan health, medical, and life insurance database with 2.9 million lines of personal information, including names, identification numbers, birthdates, addresses, and financial values.
Other examples are more indirect but still relevant to insurers. In one ransomware leak site post tied to a manufacturing victim, the threat actor claimed access to 1.7 TB of data and shared a related image showing commercial property insurance documentation. That does not make the incident an “insurance breach,” but it does show how insurance information can surface inside compromises of non-insurance organizations. Insurance data often travels within the broader business ecosystem.
On their own, some of these posts may look like noise. Together, they underscore that insurance-related data continues to be valuable, searchable, and marketable in underground spaces as threat actors continue to discuss, expose, and target the industry.
For cyber threat actors, insurance data is not just “personal information.” While personally identifiable information (PII) and protected health information (PHI) are already valuable, threat actors are also looking for ways to increase pressure, improve targeting, and make extortion attempts feel more personal and harder to ignore.
Insurance data can create a detailed picture of a person, business, policy, claim, payment history, medical context, legal matter, employment status, vendor relationship, or financial exposure. That data can be leveraged for identity theft, fraud, claims manipulation, phishing, business email compromise, extortion, credential theft, and vendor targeting. Insurance companies also hold data that can overlap with healthcare, legal, financial, and HR records. That makes the sector especially exposed when third parties are involved.
One recent dark web post claimed a 1.8 TB database tied to a Canadian organization containing financial records, HR data, PII, PHI (protected health information), partner and vendor data, accounting system data, mailboxes, and email. While the post was not insurance-specific, the data categories are highly relevant to the types of connected business information insurers often depend on when underwriting, processing claims, investigating losses, or assessing risk.
That is the larger issue: attackers do not need to compromise a major carrier directly to create insurance-sector exposure. They can target the ecosystem around it.
Insurance does not operate by itself; carriers, brokers, MGAs, TPAs, legal partners, healthcare providers, repair networks, restoration firms, financial institutions, manufacturers, real estate firms, and software vendors all exchange sensitive data. That interconnected model creates opportunities for attackers.
Recent Bitisight threat intelligence included multiple mentions of insurance claims, accident law, healthcare treatment centers, restoration services, repair-related businesses, insurance application code, and insurance documentation exposed through non-insurance breaches. Some of those mentions may be spam, low-value chatter, or unrelated to confirmed compromise. But they still reflect how often insurance-related language, records, and workflows appear across exposed online environments.
While not every post represents a breach, insurance data, systems, and adjacent services are consistently visible in places where cybercriminals look for opportunity. A third-party vendor with weak controls can become a path into sensitive customer data. Ransomware leaks from unrelated sectors can still expose insurance documents, policy information, or claim-related records that may create downstream risk.
One detail that stands out in the French insurance-related post is that it was described as a repost with a sample included because people had asked for it. Cyber risk teams often focus on the original breach or leak, but reposts can extend the lifespan of exposed data. Once information is circulating in criminal communities, it can be repackaged, sampled, combined with other datasets, and resurfaced months or years later.
Security teams need to understand whether exposed data is still being discussed, traded, or enriched. They also need to know whether credentials, access, customer data, policyholder information, or third-party records connected to their brand, subsidiaries, executives, employees, or vendors are appearing in underground spaces.
Some of the most useful signals are not labeled “insurance breach.” They may show up as claims-related data, health or medical insurance records, life insurance databases, accident law firm data, repair or restoration records, application source code, mailbox dumps, vendor access, financial records, HR files, commercial property insurance forms, or business records connected to policyholders and partners. This is why broad visibility matters. If a security team only monitors for exact brand mentions, they may miss early signs of risk across the wider ecosystem. Attackers think in terms of usefulness. They look for data that helps them impersonate, pressure, defraud, or gain access. Insurance data is useful for all of those things.
Insurance organizations should be asking practical questions:
The goal is not just to find mentions after the fact. It is to understand where exposure is building before it becomes a larger incident.
This is where Bitsight can help insurance organizations move from fragmented signals to a clearer view of cyber risk.
Bitsight gives security and risk teams external visibility into organizations, ecosystems, and third-party relationships. For insurers, that visibility is especially important because risk often extends beyond the carrier itself. Brokers, claims processors, healthcare partners, legal services, software providers, restoration firms, and other vendors can all introduce exposure.
With Bitsight, insurance teams can better understand where external risk may exist across their own organization and their broader vendor ecosystem. That includes monitoring cyber risk signals, identifying exposure across third parties, and using objective security ratings and risk insights to support better decisions.
Bitsight Threat Intelligence can also help teams track relevant activity across underground and open sources, including criminal forum chatter, claimed data leaks, ransomware leak site posts, access listings, credential exposure, and other signals that may indicate elevated risk. This gives teams more context around what attackers are discussing, what data may be circulating, and where attention may be building.
For insurance companies, this matters because the sector is not just protecting internal systems. It is protecting policyholder trust, claims integrity, sensitive records, regulated data, and a large network of third-party relationships. Bitsight helps connect those dots.
Insurance remains a high-value target because the sector holds the exact kind of data attackers want: identity, money, health, legal, employment, claims, and business relationship information.
Recent Bitsight threat intelligence reinforces that insurance-related data and access continue to appear across criminal forums, ransomware leak sites, and other underground sources. Some of this activity directly references insurance companies or insurance databases. Other activity shows insurance information surfacing through the broader ecosystem of legal, healthcare, financial, manufacturing, claims-related, and third-party partners. The attack surface is bigger than the enterprise perimeter. Monitoring needs to include the brand, the vendors, the partners, the data, the credentials, the documentation, and the dark web conversations that show where attackers are paying attention. Because when insurance data shows up in the wrong places, it does not stay isolated for long.
Get the report and see why Bitsight was named a Visionary.