Aflac
Aflac said attackers used social engineering to gain access to its network, as part of a wider cybercrime campaign against the insurance industry. (Source: Aflac statement)
Insurers govern more people who do not work for them than people who do: agents, brokers, MGAs and TPAs, each with access into policy and claims systems. The incidents below show how access into those systems gets used.
Aflac said attackers used social engineering to gain access to its network, as part of a wider cybercrime campaign against the insurance industry. (Source: Aflac statement)
Data reached through a third-party SaaS platform holding customer records, on access gained through social engineering. (Source: TechCrunch)
The common thread in both: social engineering opened the door, and how far that access reached decided how many customer records went with it.
The workforce you can offboard is the smaller half of your access. The other half is contractual, distributed and reviewed by nobody in particular. That is where the campaign that moved through the sector found its footing.
If any answer is "no" or "I would have to ask", that is the blind spot.
The two-page PDF adds the full account of each incident and the control that would have stopped it. Name and work email, and it comes straight back.
The sector page: identity security for insurance. The service that closes the gap: IGA implementation. And a free audit is 30 minutes with a certified engineer on your own environment, findings in writing: Get a free audit.
Name and work email. The two-page PDF covers each incident in full and the control that would have stopped it.
Needed for the site to work — page delivery, and the spam protection on our forms. These do not track you and cannot be switched off.
Google Analytics and Microsoft Clarity, so we can see which pages are useful and which are confusing. Clarity hides anything you type into a form. We use this to improve the site, not to identify you.
ZoomInfo WebSights, which tells us which organisation a visit is likely to have come from and which pages were read. With this on, ZoomInfo may also set third-party cookies that help it recognise a visit across other websites, and may share that with its own partners. Turning this off stops all of it.