Illumifin, an insurance technology company and third-party administrator, disclosed a data breach that was discovered on November 4, 2025. This incident involved unauthorized access to its network, compromising personal information from clients of over 100 insurance carriers. The company notified affected clients on January 9, 2026, and provided lists of impacted individuals around February 25, 2026.
The confirmed data types exposed in the breach include names, Social Security numbers, dates of birth, and addresses. The exact number of affected individuals has not been disclosed, and the full scope of states affected remains unclear due to Illumifin being a multi-state third-party administrator. Illumifin engaged a forensic firm and informed law enforcement following the discovery of the breach. No specific consumer notification date or total number notified has been detailed in the available sources, and it is known that some affected individuals were unaware Illumifin held their data.
Details about data breaches often emerge over time, and notifications to affected individuals can be delayed.