DisclosureLens
MalwareFinancial ServicesFinanceRansomwareStolen CredentialsData ExfiltratedData EncryptedCustomer Data InvolvedMulti-Stage ChainSupply Chain (3P Vendor)Identity (basic)Government IDFinancial accountHealth (basic)PHIHighContained

Landmark Admin

bd_a8d46b90940d2961 · schema v1 · pii pii-v1

Severity

High

Discovered

May 13, 2024

Filed

Apr 22, 2025

To disclose

49 weeks

Affected

1,471state residents only

Confidence

66%
Full breach record for Landmark Admin9 incidents on file

Landmark Admin, LLC, a third-party administrator for insurance carriers, notified the Rhode Island Attorney General of a cybersecurity incident discovered in May 2024. The breach involved unauthorized access via valid credentials through a VPN, followed by data encryption and exfiltration. Approximately 1,471 Rhode Island residents were potentially affected, with data including names, SSNs, driver's licenses, bank account numbers, and health information. Landmark engaged forensic investigators, notified law enforcement, and offered credit monitoring services.

Rhode Island clock RI AG >45d49 weeks discovery → filing

Incident timeline

discovery → filing · 49 weeks / 344 days

May 13, 2024

Begins

May 13, 2024

Discovered

Apr 22, 2025

Filed

vs. sector median

+41 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,471 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.