Skip to content
NetarxImpact Database
Help Desk ImpersonationNo AI reportedReported

Philadelphia Insurance Companies disclosed breach in insurer-focused campaign

Philadelphia Insurance Companies · Financial Services · United States · June 2025

What happened

Philadelphia Insurance Companies was named alongside Aflac and Erie Insurance as a victim of the June 2025 Scattered Spider campaign targeting US insurers. Reporting cited SEC filings describing theft of sensitive customer data and operational disruption at the affected carriers. The campaign followed the group's earlier attacks on UK retailers.

How the deception worked

Philadelphia Insurance has not described how it was breached. What follows is the technique researchers documented across this campaign, not a confirmed account of this intrusion: initial access came from a phone call to a corporate help desk. The caller impersonated a legitimate employee using enough personal detail to satisfy the standard verification script, then requested that a multi-factor authentication enrolment link be sent so the 'employee' could register a new phone. With MFA bound to a device they controlled, the attackers completed a self-service password reset and owned the account. Researchers reported near-identical scripting at the carriers hit in this period, which is what let a single working pretext be reused.

AI involvement · No AI reported

No AI-generated voice or video was reported in connection with this intrusion.

The control that would have caught it· our reading, not a claim from the sources

Treat MFA re-enrolment as a privileged action requiring a second, independently verified approver rather than something a front-line agent can complete on request.

Sources (1)

  1. 3 key takeaways from the Scattered Spider attacks on insurance firms
    BleepingComputer·bleepingcomputer.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.