Landmark Admin, which provides administrative services to life and health insurers, found that an attacker had accessed files containing the personal information of 806,519 people. Reported fields include names, addresses, social security numbers, passport numbers, tax identification numbers, medical information and insurance policy information.
The Full Set, In One Place
Most breaches lose a slice: contact details, or card numbers, or a medical record. This one lost the combination — government identifiers, tax numbers, travel documents and health information about the same individuals.
That is what a policy administrator holds, because underwriting a life policy requires knowing who someone is and what is wrong with them. The concentration is a function of the job.
Nobody Buys Insurance From An Administrator
A policyholder chose an insurer. The insurer chose Landmark. The policyholder was not consulted, will not recognise the name, and receives the notification from a company they have never dealt with.
This is the most common structure in the file set and insurance produces its worst version, because the data required to write a policy is exactly the data that cannot be reissued afterwards.
Compiled from the company’s notifications and public reporting, listed below. The insurers whose policyholders were affected are not enumerated in the disclosure. Corrections: corrections@forensicpost.com.
- Landmark Admin data breach impacts 806,000 peopleBleepingComputer