Mountain West Insurance & Financial Services, an independent insurance and financial services agency headquartered in Colorado, suffered a significant data breach in March 2025. An unauthorized actor gained access to multiple employee email accounts, compromising sensitive consumer information. The exposed data included full names, Social Security numbers, dates of birth, driver’s license numbers, financial account details (including access information), payment card data, passport numbers, electronic signatures, medical information, and health insurance records. The breach was discovered on March 17, 2025, but the extent of the compromise was confirmed only on August 15, 2025. Affected individuals were notified in September 2025, with the company offering credit monitoring and identity protection services. The incident poses severe risks of identity theft, financial fraud, and unauthorized access to highly sensitive personal and financial data, potentially leading to long-term harm for victims.
Source: https://www.claimdepot.com/investigations/mountain-west-insurance-data-breach-2025
Mountain West Insurance Agency, LLC cybersecurity rating report: https://www.rankiteo.com/company/mountain-west-insurance-agency-llc
"id": "mou1302913110825",
"linkid": "mountain-west-insurance-agency-llc",
"type": "Breach",
"date": "3/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Unspecified (notifications sent '
'to affected individuals)',
'industry': 'Insurance and Financial Services',
'location': {'headquarters': 'Colorado, USA',
'operations': ['Colorado',
'New Mexico',
'Nevada',
'30+ other U.S. states']},
'name': 'Mountain West Insurance & Financial Services, '
'LLC',
'size': '22+ offices, exact employee/customer count '
'unspecified',
'type': 'Independent Insurance and Financial Services '
'Agency'}],
'attack_vector': 'Compromised Employee Email Accounts',
'customer_advisories': ['Review and save notification letters',
'Enroll in credit monitoring services',
'Monitor accounts for unauthorized activity',
'Consider fraud alerts/credit freezes',
'Seek legal help for compensation'],
'data_breach': {'data_exfiltration': 'Likely (data compromised in '
'cyberattack)',
'personally_identifiable_information': ['Full name',
'Social Security '
'number',
'Date of birth',
'Driver’s license '
'number',
'Passport number',
'Electronic '
'signature'],
'sensitivity_of_data': 'High (includes SSN, financial account '
'access, medical info)',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)',
'Financial Data',
'Medical/Health Information',
'Authentication Credentials']},
'date_detected': '2025-03-17',
'date_publicly_disclosed': '2025-09-22',
'description': 'Shamis & Gentile P.A., a class action law firm, is '
'investigating a data breach at Mountain West Insurance & '
'Financial Services, LLC. Unauthorized actors gained access to '
'employee email accounts, compromising sensitive consumer '
'information including PII, financial data, and medical '
'records. Affected individuals may be eligible for '
'compensation under state and federal law.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'exposure of sensitive customer data',
'data_compromised': ['Full name',
'Social Security number',
'Date of birth',
'U.S. driver license number',
'Financial account number',
'Financial account access information',
'Payment card number',
'Payment card access information',
'Passport number',
'Electronic signature',
'Medical information',
'Health insurance information'],
'identity_theft_risk': 'High (PII and financial data exposed)',
'legal_liabilities': 'Potential lawsuits and compensation claims '
'from affected individuals',
'payment_information_risk': 'High (payment card and account access '
'information exposed)',
'systems_affected': ['Employee Email Accounts']},
'initial_access_broker': {'entry_point': 'Employee Email Accounts',
'high_value_targets': ['Consumer PII',
'Financial Data',
'Medical Records']},
'investigation_status': 'Ongoing (as of 2025-09-22, notifications sent)',
'recommendations': ['Enroll in free credit monitoring/identity protection '
'services if offered',
'Monitor financial accounts for suspicious activity',
'Place a fraud alert with credit bureaus',
'Request free annual credit reports',
'Seek legal counsel for compensation claims'],
'references': [{'source': 'Shamis & Gentile P.A. Investigation Notice'}],
'regulatory_compliance': {'legal_actions': 'Potential class-action lawsuits '
'(investigation by Shamis & '
'Gentile P.A.)'},
'response': {'communication_strategy': ['Mail notifications to affected '
'individuals',
'Website notice',
'Offer of free credit '
'monitoring/identity protection '
'services (if applicable)'],
'incident_response_plan_activated': 'Yes (investigation '
'initiated post-discovery)',
'recovery_measures': ['Notification letters mailed (2025-09-22)',
'Website notice published']},
'stakeholder_advisories': ['Mail notifications to affected individuals',
'Website notice'],
'threat_actor': 'Unauthorized Actor (Unknown)',
'title': 'Mountain West Insurance & Financial Services, LLC Data Breach',
'type': 'Data Breach (Unauthorized Access to Email Accounts)'}