Claim details
INC Ransom claimed Beacon Mutual and alleged theft of 275 GB.
Beacon Mutual detected unauthorized access Jan. 14, 2026, disconnected systems and restored production Jan. 20. The company later confirmed that files containing Social Security numbers and other sensitive information were copied; INC Ransom separately claimed responsibility and 275 GB of data.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Unauthorized access to systems, accounts, networks, or data.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.
The actor explicitly threatened to publish or publicly release victim data or incident details.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
The Beacon Mutual Insurance Company experienced confirmed ransomware and data theft. The company’s May 22 notice said an unauthorized person accessed systems from Jan. 7 to Jan. 14, 2026, and copied files. Earlier reporting said Beacon Mutual confirmed ransomware but found no encryption in its production environment. INC Ransom separately claimed responsibility and alleged theft of 275 GB; the company has not verified the actor or volume.
Beacon Mutual disconnected systems after detecting suspicious activity Jan. 14. Production was restored Jan. 20. The public record does not identify a physical-facility disruption or establish that the company’s Warwick headquarters was itself affected.
Beacon Mutual said copied files contained names with one or more of the following: Social Security numbers, driver’s-license numbers, financial-account numbers, health-insurance information or medical-treatment information. Maine’s attorney general lists 607 affected Maine residents and written notification beginning May 18.
Confidence is high that ransomware-related unauthorized access, data theft and a temporary systems shutdown occurred. Confidence is medium in the INC Ransom attribution and claimed data volume because those details rely on the actor’s posting. The initial-access method, ransom demand, payment and complete affected population remain unresolved.
The company disclosed the access period, containment, restoration and categories of copied personal information. Actor attribution remains unconfirmed.
The operational incident is resolved because production systems were restored Jan. 20. Breach notification and legal response continued afterward.
INC Ransom claimed Beacon Mutual and alleged theft of 275 GB.

We reported ransomware, restoration, the INC Ransom claim and later evidence of sensitive-data theft.
INC Ransom listed Beacon Mutual and alleged theft of 275 GB.
Insurance Journal reported unauthorized access, system disconnection, restoration and the company’s ransomware confirmation.
A summary of breach notices said stolen files contained names, Social Security numbers and potentially other sensitive identifiers.
The filing lists unauthorized access Jan. 7-14, written notice May 18 and 607 affected Maine residents.
Beacon Mutual said an unauthorized person accessed systems Jan. 7-14, copied files and exposed specified categories of personal information.
Signed-in members can report an error, update, or missing source.