{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-philadelphia-insurance-companies-disclosed-breach-in-insurer-focused-cam"},"incident":{"title":"Philadelphia Insurance Companies disclosed breach in insurer-focused campaign","date":"2025-06","date_precision":"month","victim_org":"Philadelphia Insurance Companies","sector":"Financial Services","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI-generated voice or video was reported in connection with this intrusion.","outcomes":["Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":"Scattered Spider (UNC3944)","summary":"Philadelphia Insurance Companies was named alongside Aflac and Erie Insurance as a victim of the June 2025 Scattered Spider campaign targeting US insurers. Reporting cited SEC filings describing theft of sensitive customer data and operational disruption at the affected carriers. The campaign followed the group's earlier attacks on UK retailers.","how_it_worked":"Philadelphia Insurance has not described how it was breached. What follows is the technique researchers documented across this campaign, not a confirmed account of this intrusion: initial access came from a phone call to a corporate help desk. The caller impersonated a legitimate employee using enough personal detail to satisfy the standard verification script, then requested that a multi-factor authentication enrolment link be sent so the 'employee' could register a new phone. With MFA bound to a device they controlled, the attackers completed a self-service password reset and owned the account. Researchers reported near-identical scripting at the carriers hit in this period, which is what let a single working pretext be reused.","lessons":"Treat MFA re-enrolment as a privileged action requiring a second, independently verified approver rather than something a front-line agent can complete on request.","confidence":"Reported","sources":[{"title":"3 key takeaways from the Scattered Spider attacks on insurance firms","url":"https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-philadelphia-insurance-companies-disclosed-breach-in-insurer-focused-cam","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-philadelphia-insurance-companies-disclosed-breach-in-insurer-focused-cam"}}