DisclosureLens
HackingFinancial ServicesTechnologyFinanceStolen CredentialsRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedMulti-Stage ChainSupply Chain (3P Vendor)Identity (basic)Government IDFinancial accountHealth (basic)PHIHighContained

Landmark Admin

bd_1baf85090385207d · schema v1 · pii pii-v1

Severity

High

Discovered

May 13, 2024

Filed

Apr 10, 2025

To disclose

47 weeks

Affected

10,150state residents only

Confidence

66%
Full breach record for Landmark Admin9 incidents on file

Landmark Admin, LLC, a third-party administrator for insurance carriers, reported a cybersecurity incident discovered on May 13, 2024. An unauthorized party accessed the network via valid credentials through a VPN, exfiltrated data, and encrypted systems. The incident affected 10,150 Iowa residents, compromising names, SSNs, driver's licenses, bank account numbers, and health information. Landmark engaged forensic investigators, notified law enforcement, enhanced security controls (MFA, firewalls, reimaging devices), and offered credit monitoring services.

Iowa clock IA AG >5 bday47 weeks discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 47 weeks / 332 days

May 13, 2024

Begins

May 13, 2024

Discovered

Apr 10, 2025

Filed

vs. sector median

+39 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed10,150 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.