Telcom Insurance Group
bd_dcc0d8949225e766 · schema v1 · pii pii-v1
Full breach record for Telcom Insurance Group →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Lynx on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Telcom Insurance Group specializes in providing business insurance solutions tailored for the telecommunications industry, including cybersecurity, worker's compensation, and directors and officers insurance. The company offers comprehensive property and casualty products through partnerships with reputable insurance providers. Their services also include risk management consulting, loss prevention, and claims advocacy, ensuring clients receive customized and trusted support. Telcom Insurance Group aims to support rural telecommunications organizations with quality service and competitive premiums.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
May 15, 2025
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Indiana State AGbd_3755a81e91889f272025-08-08 · +85dVerified by operator
- Massachusetts State AGbd_34a691a64e5865b82025-11-19 · +188dVerified by operator
- Vermont State AGbd_65b156e4aa9615c12025-11-19 · +188dVerified by operator
- New Hampshire State AGbd_80a3dc02e3a898682025-11-19 · +188dVerified by operator
Show 1 more filing ↓Show fewer ↑up to 188d gap
- Montana State AGbd_98fb7d6761f94c2b2025-11-19 · +188dVerified by operator
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing May 15, last Nov 19 (MT) — a 188-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
lynx
According to ransomware.live, Lynx is a ransomware-as-a-service operation that emerged in mid-2024 as a rebrand of INC Ransomware (whose source code was sold for $300,000 on the RAMP forum), claiming ~300 victims across manufacturing, business services, technology, and transportation with an 80/20 profit split for affiliates.