Alpine Agency of the Midlands
Incident posture
Linked entities
- Victim
- Alpine Agency of the Midlands
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Alpine Agency of the Midlands reported unusual email account activity in November 2025, leading to investigation of unauthorized access to its email system.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Alpine Agency of the Midlands, LLC, a small, independent health and benefits insurance company headquartered in Columbia, South Carolina, disclosed a security incident involving unauthorized access to an employee email account. The company provides services to insurance carriers, employers, and health plans, and in the course of that work it is provided with certain health data by its clients. The disclosure described the event as a targeted intrusion into its email environment rather than a broader network compromise, with the investigation determining that the impact was confined to a single employee mailbox. Because Alpine handles protected health information on behalf of its insurance and benefits clients, the data exposed in the affected account related directly to the individuals whose information was held in correspondence and attachments on the company's email system.
Unusual activity within the employee email account was first identified in November 2025. Upon detecting the anomaly, Alpine moved to secure the account and launched an investigation to determine the nature and scope of the unauthorized activity. The subsequent review confirmed that the affected email account had been first accessed by an unauthorized third party on October 28, 2026. During the period the account was under unauthorized control, the attacker was able to access mail and associated attachments contained within that mailbox, and emails and their attachments may have been copied by the attacker. The exact duration of the unauthorized access window beyond the initial entry date and the precise number of messages or attachments reviewed by the intruder were not described in the available information.
A review of the contents of the compromised mailbox was undertaken to identify what categories of personal and protected health information had been exposed. That review determined that the account held first and last names, addresses, dates of birth, health insurance information, and limited Social Security numbers. The disclosure indicated that the Social Security numbers that were present represented a limited subset of the data within the account rather than every individual's record. Other categories commonly associated with benefits administration correspondence, such as detailed clinical records or financial account credentials, were not enumerated in the source material. Notifications were to be mailed to the affected individuals once the file-level review was completed, with the organization indicating that the breach had been reported to the U.S. Department of Health and Human Services' Office for Civil Rights as affecting at least 500 individuals, a figure that Alpine stated would be updated once the review concluded.
The organization's response to the incident centered on containment of the affected mailbox, engagement of an investigation process to characterize the scope of exposure, and subsequent regulatory reporting and individual notification. The account was secured once the unusual activity was identified, and Alpine indicated it was continuing to evaluate the contents of the mailbox to identify each affected individual so that direct notice could be provided. Reporting to the HHS Office for Civil Rights placed the matter within the formal breach notification framework applicable to HIPAA-regulated entities and business associates. No statement was provided in the source material regarding whether credit monitoring or identity theft protection services were being offered to affected individuals, whether law enforcement had been notified, or whether third-party cybersecurity professionals had been engaged to assist with the forensic review, and no threat actor or hacking group was identified as having claimed responsibility for the intrusion.
Sources
Sources available to members: 1 source.