lockbit2 attacks specialinc

Incident Date:

March 17, 2022

World map

Overview

Title

lockbit2 attacks specialinc

Victim

specialinc

Attacker

Lockbit2

Location

Plano, USA

Texas, USA

First Reported

March 17, 2022

Special Insurance Services, Inc. Ransomware Attack

Special Insurance Services, Inc. (SIS), a prominent entity in the insurance sector, recently fell victim to a ransomware attack orchestrated by the Lockbit2 group. This incident was disclosed on the group's dark web leak site. Founded in 1987, SIS operates as an independent entity, facilitating agents in crafting client programs throughout the United States.

The firm's online platform details its offerings, which span custom benefit programs and insurance services tailored for a diverse clientele, including employers, employees, owner operators, contractors, associations, schools, and more. SIS's robust partnerships with underwriters and reinsurers underscore its capability to efficiently serve its clients.

The insurance industry's repository of sensitive personal and financial data makes it an attractive target for cybercriminals. In 2023 alone, the sector saw significant ransomware attacks on entities like Point32Health, the conglomerate behind Harvard Pilgrim Health Care and Tufts Health Plan, and NationsBenefits, a healthcare benefits provider based in Florida.

To counteract the threat of ransomware, insurance firms are urged to bolster their core IT infrastructures and ancillary platforms, including agency portals, online policy applications, and digital interfaces for claim submissions. Moreover, as these companies evolve and broaden their service spectrum, prioritizing cybersecurity to safeguard data becomes imperative.

The cyber assault on Special Insurance Services, Inc. underscores the critical need for heightened cybersecurity vigilance within the insurance industry. It is essential for companies to deploy comprehensive security strategies to protect not only their clients' data but also their proprietary information.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.