MagMutual Insurance Co. Discloses Data Breach Affecting Healthcare Providers
MagMutual Insurance Co., a physician-owned medical malpractice insurer based in Atlanta, revealed a data breach involving unauthorized access to its systems. The company, which serves over 50,000 healthcare providers nationwide, detected suspicious activity on April 28, 2026, and confirmed ongoing unauthorized access by May 3, 2026.
An investigation, supported by third-party cybersecurity experts, determined that an unauthorized party accessed MagMutual’s network between April 28 and May 4, 2026, potentially exfiltrating sensitive files. On June 23, 2026, the threat actor Leaknet claimed on a dark web forum to have obtained MagMutual’s data, threatening to publish it within days.
The exposed information may include names, clinical details, demographic data, and financial records. MagMutual has posted a breach notice on its website and set up a dedicated helpline (888-289-7022) and mailing address for affected individuals.
The incident underscores the growing risk of cyber threats targeting healthcare-related entities and the potential for sensitive patient and provider data to be compromised.
Source: https://www.claimdepot.com/data-breach/magmutual-insurance-company-2026
MagMutual cybersecurity rating report: https://www.rankiteo.com/company/mag-mutual
"id": "MAG1784759901",
"linkid": "mag-mutual",
"type": "Breach",
"date": "4/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Healthcare/Insurance',
'location': 'Atlanta, USA',
'name': 'MagMutual Insurance Co.',
'size': '50,000+ healthcare providers served',
'type': 'Insurance Company'}],
'attack_vector': 'Unauthorized Access',
'customer_advisories': 'Breach notice on website, dedicated helpline '
'(888-289-7022), and mailing address for affected '
'individuals',
'data_breach': {'data_exfiltration': True,
'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Names',
'Clinical details',
'Demographic data',
'Financial records']},
'date_detected': '2026-04-28',
'date_publicly_disclosed': '2026-06-23',
'description': 'MagMutual Insurance Co., a physician-owned medical '
'malpractice insurer, disclosed a data breach involving '
'unauthorized access to its systems. The breach potentially '
'exposed sensitive files, including names, clinical details, '
'demographic data, and financial records of healthcare '
'providers and patients.',
'impact': {'data_compromised': 'Sensitive files including names, clinical '
'details, demographic data, and financial '
'records',
'identity_theft_risk': 'High',
'payment_information_risk': 'High',
'systems_affected': 'MagMutual’s network'},
'initial_access_broker': {'data_sold_on_dark_web': True},
'investigation_status': 'Ongoing',
'motivation': 'Data Exfiltration',
'ransomware': {'data_exfiltration': True},
'references': [{'source': 'MagMutual Breach Notice'}],
'response': {'communication_strategy': 'Breach notice on website, dedicated '
'helpline (888-289-7022), and mailing '
'address for affected individuals',
'third_party_assistance': 'Cybersecurity experts'},
'threat_actor': 'Leaknet',
'title': 'MagMutual Insurance Co. Data Breach',
'type': 'Data Breach'}