Churchill Claims Services, Inc.
bd_f8817f2de5186b0e · schema v1 · pii pii-v1
Full breach record for Churchill Claims Services, Inc. →2 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Securotrop on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Status: AWAITING Size: 240 GB
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Oct 9, 2025
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- New Hampshire State AGbd_533d0ae003a5405d2026-04-27 · +200dVerified
- Nebraska State AGbd_8764e5ad5d719a862026-04-27 · +200dVerified by operator
- Indiana State AGbd_a2237f9466e1fa702026-04-27 · +200dVerified
- Massachusetts State AGbd_28b153d3712f67fc2026-04-28 · +201dVerified by operator
Show 1 more filing ↓Show fewer ↑up to 201d gap
- Vermont State AGbd_2b2dc5068bbe5e922026-04-28 · +201dVerified
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing Oct 9, last Apr 28 (VT) — a 201-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
securotrop
According to ransomware.live, Securotrop is a ransomware group established in early 2025 that operates within the Qilin affiliate network while maintaining an independent public identity, focusing exclusively on commercial targets and deliberately avoiding healthcare and government entities, with approximately 32 documented victims.