Cyber Risk in Insurance: Why the Front Door Is Now the Help Desk
- Aug 11
- 5 min read
Why insurers have become the target
Insurance companies now hold some of the most sought-after data of any industry, and criminals have noticed.
In June 2025, three of the best-known names in US insurance, Aflac, Erie Insurance and Philadelphia Insurance Companies, all reported cybersecurity incidents within the same fortnight. Aflac was hit hardest. What began as an intrusion contained within hours went on to expose the personal information of roughly 22.6 million people: Social Security numbers, health records and claims data among them. Google's Threat Intelligence Group had warned days earlier that the group behind the 2023 MGM Resorts and Caesars attacks, known as Scattered Spider, had shifted its focus from retail to insurance. The warning proved accurate almost immediately.
This was not an isolated event. It was the latest move in a pattern, and it is unlikely to be the last time an insurer finds itself the target rather than the responder.
The method matters more than the malware
These intrusions rarely start with code. They start with a convincing phone call.
Scattered Spider's signature approach is social engineering aimed squarely at IT help desks and call centres. Operators impersonate employees, request password or multi-factor authentication resets, and register fraudulent login pages that mimic a company's real support portals. CISA and the FBI have documented the wider toolkit in joint advisories: SIM-swap attacks, push-bombing, credential harvesting, and, where it serves the group's purpose, ransomware deployment once access is secured. None of it requires a technical vulnerability. It requires one support agent, under time pressure, persuaded that the person on the line is who they claim to be.
For an organisation built around trust and verification, that is an uncomfortable truth. The weak point is rarely the network. It is a human decision made in a moment, without the benefit of hindsight.
Why the exposure runs deeper than one bad actor
Large help desks, outsourced IT and vast data holdings make insurers a structurally attractive target, not just an unlucky one.
Insurers sit on rich, concentrated stores of personal, medical and financial information, exactly the combination that makes a successful breach valuable to criminals, whether the goal is extortion, identity theft or resale. They also run the kind of large, often outsourced support operations that give social engineers plenty of surface area to work with: agents, policyholders and employees all needing routine password and access resets, at scale, every day.
There is a pattern to how groups like Scattered Spider operate, too. They tend to concentrate on one sector at a time, extracting value before defences catch up, then move on. Casino operators in 2023. Retailers through early 2025. Insurers by that summer. Security researchers have been explicit that this is a deliberate strategy, not coincidence, and it is a reasonable assumption that
another sector is already being scoped for what comes next.
The numbers behind the headlines
The 2025 spree landed inside a much wider pattern of record breach costs and record claims.
IBM's most recent Cost of a Data Breach report put the global average cost of a breach at $4.99 million, up 12% year over year, with breaches in the US running far higher once regulatory penalties and business disruption are factored in. Criminal and malicious attacks, rather than accidents or system error, now account for 55% of all breaches. On the claims side, cyber insurer At-Bay's 2026 InsurSec report recorded a 7% year-over-year rise in claim frequency and an all-time high in average severity. Ransomware was the costliest category, with remote access services, VPNs in particular, the entry point in 87% of ransomware claims.
Businesses that reported an incident within three days recovered stolen funds roughly 70% of the time. Past two weeks, that figure fell below 30%. The pattern in that data is consistent with what happened at Aflac, Erie and Philadelphia Insurance: speed and preparation, not just security spend, are what separate a contained incident from a prolonged one.
Regulators are watching the clock too
A six-month gap between discovery and notification is exactly the kind of detail regulators, and claimants, focus on.
Aflac's intrusion was discovered on 12 June 2025. Notifications to affected individuals did not begin until late December, after the company determined in early December what personal information had actually been exposed. A proposed class action followed within days of the breach becoming public. The NAIC's Insurance Data Security Model Law, adopted in some form by 28 states and jurisdictions as of last year, requires insurers to maintain a formal information security programme, investigate incidents and notify state commissioners when they occur.
The framework is real, but the gap between an intrusion and a clear public account of it remains one of the hardest parts of any incident to manage well, legally and reputationally.
Preparedness is a leadership question, not just an IT one
The organisations that hold up best have usually decided, in advance, who owns these decisions and how they get made.
It is tempting to treat a cyber incident as a technical problem, contained by the IT and security teams and reported on once resolved. In practice, the decisions that shape the outcome sit with leadership from the first hour: whether to disclose early or wait for clarity, what to tell regulators, reinsurers and key clients and in what order, how to support affected policyholders and staff, and who has the authority to make those calls under pressure.
These are the same judgement calls that determine how any crisis, reputational or operational, plays out in public. They are difficult to make well for the first time while the pressure is real, which is why organisations that handle these moments well have typically rehearsed them beforehand, at senior level, under realistic conditions.
Frequently asked questions
What makes insurance companies a target for cybercriminals?
Insurers combine two things attackers want: large concentrations of sensitive personal, medical and financial data, and large support operations, help desks, call centres and outsourced IT, that are exposed to social engineering. Threat groups have also shown a pattern of targeting one sector at a time, and insurance was next after retail through 2025.
Is a cyberattack on an insurer a cybersecurity problem or a crisis management problem?
Both, and treating it as only the former is a common mistake. Containing the intrusion is a technical task. Deciding what to disclose, when, to whom, and how to support those affected are leadership decisions that shape the reputational and regulatory outcome long after the technical incident is resolved.
What should an insurer do first if it suspects a breach?
Establish who has decision-making authority before the facts are fully known, engage legal, security and communications advisers early, and resist the urge to either go silent or overpromise before the picture is clear. Organisations that have already rehearsed this sequence tend to move through it with far more control than those improvising for the first time.
Concerned about how your organisation would hold up?
A discreet conversation before an incident happens is usually the most valuable one.
Whether you want an honest view of your exposure or support in preparing your leadership team to respond well under pressure, we are happy to talk it through quietly and without obligation.
About SJ Group International
SJ Group International is a discreet, executive led consultancy supporting clients through security, risk and crisis matters.
SJ Group International advises high net worth families, family offices, corporates, boards, law firms and insurers on security, risk, crisis management and preparedness. The group has served clients internationally since 2019 and is known for calm, senior-level support delivered with discretion. Leadership teams can also test their readiness through immersive crisis simulations at the Academy at Bylaugh.