Insurance giant Globe Life facing extortion attempts after data theft from subsidiary

Avatar

Insurance firm Globe Life is being extorted by hackers after data on more than 5,000 people was stolen from a subsidiary.

The company told regulators at the U.S. Securities and Exchange Commission (SEC) that it reported the incident to federal law enforcement. 

“Based on the Company’s investigation to date, which remains ongoing, the Company believes that information relayed to the Company by the threat actor may relate to certain customers and customer leads that can be traced to the Company’s subsidiary, American Income Life Insurance Company,” the company explained in the filing. Globe Life declined to comment for this article.

The stolen information includes Social Security numbers, names, addresses, health-related data and more. Globe Life warned that the “full scope of information possessed by the threat actor has not been fully verified.” 

“Most recently, the threat actor also shared information about a limited number of individuals to short sellers and plaintiffs’ attorneys,” the filing adds. “The threat actor claims to possess additional categories of information, which claims remain under investigation and have not been verified.” 

The Texas-based insurance giant said the extortion attempts did not involve ransomware or any cyberattack that disrupted company operations. 

In June, the company told the SEC about an inquiry from a state insurance regulator about “potential vulnerabilities related to access permissions and user identity management for a Company web portal that likely resulted in unauthorized access to certain consumer and policyholder information.” 

The company hired cybersecurity experts to investigate the situation and remediate the incident. 

Globe Life reported $5.21 billion in revenue last year and American Income Life Insurance Company is one of its premiere brands — with more than 4 million policies in force and about $297 million in annualized life premium sales.

CybercrimeNewsNews BriefsPrivacy
Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

 

Total
0
Shares
Previous Post

More than 5,000 arrested, thousands of websites disrupted in crackdown on illegal gambling during Euro tournament

Next Post

Japan’s ruling political party hit by cyberattack from alleged pro-Russian hackers

Related Posts

Commvault Confirms Hackers Exploited CVE-2025-3928 as Zero-Day in Azure Breach

Enterprise data backup platform Commvault has revealed that an unknown nation-state threat actor breached its Microsoft Azure environment by exploiting CVE-2025-3928 but emphasized there is no evidence of unauthorized data access. "This activity has affected a small number of customers we have in common with Microsoft, and we are working with those customers to provide assistance," the company
Avatar
Read More

Beyond Vulnerability Management – Can You CVE What I CVE?

The Vulnerability Treadmill The reactive nature of vulnerability management, combined with delays from policy and process, strains security teams. Capacity is limited and patching everything immediately is a struggle. Our Vulnerability Operation Center (VOC) dataset analysis identified 1,337,797 unique findings (security issues) across 68,500 unique customer assets. 32,585 of them were distinct
Avatar
Read More