Menu
Browse

Cyber Incident Victim: Beacon Mutual Insurance Co.

Date:

Jan 2026

Location:

United States of America

Summary

Beacon Mutual Insurance Co. learned of suspicious activity on its network and contained a ransomware attack that allowed an unauthorized party to access systems and copy files containing personal information such as names, Social Security numbers, driver’s license numbers, financial account details, and health or medical data. The insurer determined that about 162,000 individuals may have been affected, primarily in Rhode Island with smaller numbers in Massachusetts and Maine, and began mailing notification letters while offering a contact line for questions. Investigators linked the incident to the ransomware group INC Ransom, which claimed to have exfiltrated 275 gigabytes of uncompressed files including employees’ and claimants’ personally identifiable information, internal financial records, correspondence, and detailed workers’ compensation claims. The company stated it is enhancing network security to prevent future incidents and is cooperating with law enforcement.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On January 14, 2026, Beacon Mutual Insurance Co. received an alert of suspicious activity on its network and promptly disconnected certain systems while launching a forensic investigation with external cybersecurity experts. The company reported that operations were restored by January 20, 2026, after the containment efforts. Subsequent investigation determined that an unauthorized party gained access to some of Beacon Mutual’s systems between January 7 and January 14, 2026, and acquired copies of certain data files. Ransomware.Live posted information indicating that the threat group INC Ransom claimed responsibility for the attack and shared a screenshot alleging that 275 GB of uncompressed/internal files and confidential information were compromised.

Cyber Incident Image

The investigation found that one or more of the breached files contained a first name or first initial and last name combined with one or more of a Social Security number, driver’s license number, financial account number, health insurance information, or medical treatment information. Beacon Mutual estimated that approximately 162,000 individuals may have been affected, including 131,207 residents of Rhode Island, 11,890 in Massachusetts, and 607 in Maine. Beginning on May 26, 2026, the insurer started mailing notification letters to those whose personal information might have been involved and provided a contact number, 833-918-8448, for questions. The company also stated that it had contacted the Federal Bureau of Investigation and would cooperate in their investigation, and that it would continue to take steps to enhance the security of its computer network to prevent similar incidents.

Beacon Mutual, headquartered in Warwick, Rhode Island, is the primary workers’ compensation insurer in that state and also underwrites policies in Massachusetts and Connecticut; in 2024 it reported revenues exceeding $118 million and employed about 100 people. The insurer noted that it maintains a comprehensive information security program aligned with recognized industry standards and regularly reviews and updates its safety measures as part of an ongoing risk‑management process. The article also referenced that, prior to this incident, Farmers Insurance had warned of a potential breach affecting over one million customers, Erie Insurance had experienced a month‑long network outage from a non‑ransomware cyberattack with no data breach, and Philadelphia Insurance had suffered a cyberattack without ransom that resulted in some data theft.

Sources
Sources available to members
2 sources