The Maine Office of the Attorney General disclosed a data breach at Gerber Life Insurance Company, uncovered on December 5, 2024, and reported on January 9, 2025. The incident stemmed from insider wrongdoing, where an internal actor improperly accessed or mishandled sensitive data. The breach exposed personal information of 273 individuals, including at least one Maine resident. While the exact nature of the compromised data (e.g., financial records, health details, or identifiers) was not specified, the involvement of an insider suggests a targeted or negligent leak of employee-managed records. Such incidents often erode trust, trigger regulatory scrutiny, and may lead to financial liabilities or reputational harm. The limited scope (273 individuals) indicates containment, but the insider threat vector raises concerns about internal controls and the potential for broader undetected exposure. No evidence of ransomware, external cyberattacks, or systemic outages was reported.
TPRM report: https://www.rankiteo.com/company/gerber-life-insurance-company
"id": "ger723082025",
"linkid": "gerber-life-insurance-company",
"type": "Breach",
"date": "11/2024",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': '273 individuals (including 1 '
'Maine resident)',
'industry': 'Financial Services (Insurance)',
'location': 'United States (specific location '
'unspecified)',
'name': 'Gerber Life Insurance Company',
'type': 'Insurance Provider'},
{'industry': 'Legal/Regulatory',
'location': 'Maine, USA',
'name': 'Maine Office of the Attorney General',
'type': 'Government Agency'}],
'attack_vector': 'Insider Threat',
'data_breach': {'number_of_records_exposed': '273',
'personally_identifiable_information': True,
'sensitivity_of_data': 'High (PII)',
'type_of_data_compromised': 'Personal Information (PII)'},
'date_detected': '2024-12-05',
'date_publicly_disclosed': '2025-01-09',
'description': 'The Maine Office of the Attorney General reported a data '
'breach involving Gerber Life Insurance Company on January 9, '
'2025. The incident, which was discovered on December 5, 2024, '
'involved insider wrongdoing and potentially exposed personal '
'information of 273 individuals, including one resident of '
'Maine.',
'impact': {'brand_reputation_impact': 'Potential (due to public disclosure)',
'data_compromised': 'Personal Information',
'identity_theft_risk': 'Potential (PII exposed)'},
'investigation_status': 'Disclosed (ongoing details unspecified)',
'post_incident_analysis': {'root_causes': 'Insider wrongdoing'},
'references': [{'date_accessed': '2025-01-09',
'source': 'Maine Office of the Attorney General'}],
'regulatory_compliance': {'regulatory_notifications': 'Maine Office of the '
'Attorney General (as '
'per state breach '
'notification laws)'},
'response': {'communication_strategy': 'Public disclosure via Maine AG '
'office'},
'threat_actor': 'Insider (Employee/Associate)',
'title': 'Gerber Life Insurance Company Data Breach (2024)',
'type': 'Data Breach'}