Skip to content

Beacon Mutual ransomware and data breach

Summary

The Beacon Mutual Insurance Company logo

Beacon Mutual detected unauthorized access Jan. 14, 2026, disconnected systems and restored production Jan. 20. The company later confirmed that files containing Social Security numbers and other sensitive information were copied; INC Ransom separately claimed responsibility and 275 GB of data.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted location

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

Extortion indicators

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

The Beacon Mutual Insurance Company experienced confirmed ransomware and data theft. The company’s May 22 notice said an unauthorized person accessed systems from Jan. 7 to Jan. 14, 2026, and copied files. Earlier reporting said Beacon Mutual confirmed ransomware but found no encryption in its production environment. INC Ransom separately claimed responsibility and alleged theft of 275 GB; the company has not verified the actor or volume.

Operational significance

Beacon Mutual disconnected systems after detecting suspicious activity Jan. 14. Production was restored Jan. 20. The public record does not identify a physical-facility disruption or establish that the company’s Warwick headquarters was itself affected.

Data impact

Beacon Mutual said copied files contained names with one or more of the following: Social Security numbers, driver’s-license numbers, financial-account numbers, health-insurance information or medical-treatment information. Maine’s attorney general lists 607 affected Maine residents and written notification beginning May 18.

Confidence and uncertainty

Confidence is high that ransomware-related unauthorized access, data theft and a temporary systems shutdown occurred. Confidence is medium in the INC Ransom attribution and claimed data volume because those details rely on the actor’s posting. The initial-access method, ransom demand, payment and complete affected population remain unresolved.

Disclosure posture

The company disclosed the access period, containment, restoration and categories of copied personal information. Actor attribution remains unconfirmed.

Current status

The operational incident is resolved because production systems were restored Jan. 20. Breach notification and legal response continued afterward.

Threat actor and claim

Listed as: Beacon Mutual InsuranceSource: ransomware.livePublished:

Claim details

INC Ransom claimed Beacon Mutual and alleged theft of 275 GB.

Organizations involved

Impacted location

Sources

Beacon Mutual ransomware incident exposes sensitive data

We reported ransomware, restoration, the INC Ransom claim and later evidence of sensitive-data theft.

Beacon Mutual Insurance — INC Ransom claim

INC Ransom listed Beacon Mutual and alleged theft of 275 GB.

Beacon Mutual confirms ransomware incident

Insurance Journal reported unauthorized access, system disconnection, restoration and the company’s ransomware confirmation.

Beacon Mutual data breach investigation

A summary of breach notices said stolen files contained names, Social Security numbers and potentially other sensitive identifiers.

Beacon Mutual data breach notice

The filing lists unauthorized access Jan. 7-14, written notice May 18 and 607 affected Maine residents.

Beacon Mutual addresses data security incident

Beacon Mutual said an unauthorized person accessed systems Jan. 7-14, copied files and exposed specified categories of personal information.

See something that needs correction?

Signed-in members can report an error, update, or missing source.