CSIDB logo
Incident

Beacon Mutual Insurance Co.

Incident posture

Attack window
Jan 2026
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-08-17 13:18

Linked entities

Victim
Beacon Mutual Insurance Co.
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Jan 2026
Discovered
Jan 2026
Disclosed
Jan 2026
Resolved
Jan 2026

Summary

Beacon Mutual Insurance Co. experienced a ransomware attack that led to unauthorized access to its systems and the acquisition of files containing personal information such as names combined with Social Security numbers, driver’s license numbers, financial account details, health insurance data, and medical records. The breach affected approximately 162,000 individuals, including about 131,000 in Rhode Island, 12,000 in Massachusetts, and 600 in Maine. The ransomware group INC Ransom claimed responsibility and asserted that 275 GB of uncompressed internal files were exfiltrated. After detecting the activity, the company isolated affected systems, launched a forensic investigation with external experts, restored operations, and began notifying those whose information may have been involved while providing a contact number for inquiries. The company also reported cooperating with the Federal Bureau of Investigation and stated it is enhancing network security to prevent future incidents.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 14, 2026, Beacon Mutual Insurance Co. received an alert of suspicious activity on its network. The company responded by disconnecting certain systems and launching a forensic investigation with external cybersecurity experts. Operations were restored by January 20, 2026. The investigation determined that an unauthorized person had gained access to some of Beacon Mutual’s systems between January 7 and January 14, 2026, and had acquired copies of certain data files.

The accessed files contained individuals’ first name or first initial and last name combined with one or more of a Social Security number, driver’s license number, financial account number, health insurance information, or medical treatment information. Based on the investigation, Beacon Mutual estimated that about 162,000 people may have been affected, including 131,207 residents of Rhode Island, 11,890 in Massachusetts, and 607 in Maine. The ransomware tracking site Ransomware.Live posted information indicating that the threat group INC Ransom claimed responsibility for the attack, and a leaked screenshot from the group asserted that the breach involved 275 GB of uncompressed/internal files containing personally identifiable information of employees, claimants, and insured workers, internal financial statements, correspondence, operational content, detailed workers’ compensation claims data, and medical records. A Beacon Mutual spokesperson confirmed the incident was a ransomware attack but could not confirm the attacker’s identity at that time.

In cooperation with the investigation, Beacon Mutual contacted the Federal Bureau of Investigation and stated it would assist in their inquiry. The company also worked with experts to analyze the potential data involved and, upon confirming unauthorized access to personal information, began mailing notification letters to affected individuals on May 26, 2026, providing a contact number (833-918-8448) for questions. Beacon Mutual said it has taken, and will continue to take, steps to enhance the security of its computer network to prevent similar incidents. The insurer, headquartered in Warwick, Rhode Island, is the primary workers’ compensation provider in the state and also underwrites policies in Massachusetts and Connecticut; in 2024 it reported revenue exceeding $118 million and employed approximately 100 people.

Sources

Sources available to members: 2 sources.

CSIDB