Skip to main content
Back to overview
High

Landmark Admin Reports Data Breach Affecting Over 800,000 Individuals

More than 2.6 million individuals were impacted by two data breaches at insurance administrator Landmark Admin and software solutions provider Young Consulting, according to fresh filings with regulatory agencies.

Key points

  • Approximately 800,000 individuals initially reported, later updated to 1,613,773 individuals affected.
  • Exposed data includes names, addresses, Social Security numbers, driver's license numbers, state identification card numbers, passport numbers, bank account and routing numbers, medical information, health insurance policy numbers, dates of birth, an
  • The company detected suspicious activity on May 13, 2024, and was breached again on June 17, 2024, during the investigation.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Oct 31, 2024
Updated
Jul 22, 2026
Confidence
High
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

LandmarkadminData DisclosureAffecting OverIndividuals MoreLandmark Admin andYoung ConsultingIn OctoberLandmark AdminPersonalMaine Attorney General

Quick context

Questions about this signal

What happened in this signal?

More than 2.6 million individuals were impacted by two data breaches at insurance administrator Landmark Admin and software solutions provider Young Consulting, according to fresh filings with regulatory agencies. In October 2024, Landmark Admin notified roughly 800,000 people that it fell victim to a ransomware attack that also included the theft of sensitive data. The company said it flagged the unauthorized access to its systems on May 13, but was breached again on June 17, while the investigation was in progress. Personal information such as names, addresses, dates of birth, drivers’ license numbers, government ID and passport numbers, Social Security numbers, medical and health insurance information, and financial information was stolen in the attack. In a filing with the Maine Attorney General’s Office last week, the third-party insurance administrator revealed that stolen credentials for its VPN service were used in the attack. The company also said that it could not determine whether the files stolen from its environment indeed contained personal information, and that it has no evidence that personal information was exfiltrated. “Although the investigation found data had been exfiltrated, it was unable to identify which specific files/folders were exfiltrated after the threat actor re-entered Lankmark’s systems.” Advertisement. Scroll to continue reading. Landmark Admin also told the Maine AGO that the incident likely impacted 1,613,773 individuals, more than double than estimated in October 2024. Last week, Young Consulting too updated its estimated impact of a data breach it suffered in April 2024, informing the Maine AGO that 1,020,108 people were potentially affected, up from the initial estimate of 954,177 . The company says that it has been conducting a comprehensive review of the compromised data, and that it determined in January 2025 that the incident affected more individuals than initially estimated. “The personal information that could have been subject to unauthorized access includes name, Social Security number, tax ID number, and health information,” Young Consulting told the Maine AGO. In May last year, the BlackSuit ransomware group claimed the attack on Young Consulting and has since made the data allegedly stolen from the company available for download. Related: 1.6 Million Impacted by Data Breach at Laboratory Services Cooperative Related: 500,000 Impacted by Pennsylvania Teachers Union Data Breach Related: 170,000 Impacted by Data Breach at Chord Specialty Dental Partners Related: Numotion Data Breach Impacts Nearly 500,000 People Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

When was this signal reported?

Shadow Tier lists Oct 31, 2024 as the signal date.

Which organization is connected to this signal?

Landmarkadmin is the organization connected to this public signal.

Explore Landmarkadmin
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence