Desk live·
ForensicPost
Insurance/Ransomware/File 21-0516

AXA Confirmed Ransomware in Four Asian Markets Nine Days After Its French Ransom Decision

Avaddon listed the insurer on May 15, 2021, claiming 3 terabytes of medical and claims data from operations in Thailand, Malaysia, Hong Kong and the Philippines. AXA confirmed an attack and access to data at its Thai assistance unit. The volume claim was never verified.

Constructed geometry · not a chart of case data
JurisdictionThailandBangkokthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetAXA Asia Assistance
ActorAvaddon
S. Rosler8 min readConfidence: medium3 sources reviewed

The Avaddon ransomware operation added AXA to its leak site around May 15, 2021, and gave the insurer 10 days to negotiate. The group claimed 3 terabytes of data from AXA’s Asia Assistance division, including customer medical reports, claims, payment and bank details, identity documents and correspondence with hospitals. It posted about 20 screenshots and, by its own account, ran denial-of-service attacks against AXA websites in four countries at the same time.

AXA Partners confirmed on Sunday, May 16, that a targeted ransomware attack had affected IT operations of Asia Assistance in Thailand, Malaysia, Hong Kong and the Philippines, and that certain data processed by Inter Partners Assistance in Thailand had been accessed. It said there was no evidence any further data was accessed and that regulators and business partners had been informed. Its Thai affiliate, Krungthai-AXA, issued a statement on May 18.

Nine Days

AXA had announced on May 6 that its French arm would stop reimbursing ransom payments, filed at 21-0506. The attack on its Asian units followed nine days later and was widely reported as a response. No evidence connects the two beyond the calendar. Avaddon did not say so, AXA did not say so, and the group’s targeting that month included an Irish health service and a New Zealand hospital network. The file records the coincidence and declines to promote it.

What Was Confirmed And What Was Claimed

AXA confirmed an attack, four affected markets and data access at one Thai processor. Avaddon claimed 3 terabytes and a field list that would make this among the most sensitive insurance breaches on record. No affected-person count, ransom figure, payment or regulatory outcome was ever published, and no confirmation that the claimed data was published after the deadline was found. The gap is the standard one this database applies to every leak-site listing: the claim is the attacker’s, and it cost nothing to make.

Avaddon shut down in June 2021 and released its decryption keys. Whatever it held on AXA’s customers went with it, or did not.

How we reported this

Compiled from AXA’s statements as reported and contemporaneous coverage, listed below. The 3-terabyte figure and the data description are Avaddon’s claims and are labelled as such. No count, payment or outcome was established, and the file is graded medium on that basis. Corrections: corrections@forensicpost.com.

Sources
  1. Insurer AXA hit by ransomware after dropping support for ransom paymentsBleepingComputer
  2. AXA Confirms Ransomware Attack Impacted Operations in AsiaSecurityWeek
  3. Ransomware Attacks Hit AXA’s Asia Units, New Zealand Health ProviderInsurance Journal (AP)
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary