illumifin
ent_4934d740df60701bbc049357
Disclosures
14
State AG · HHS OCR · 12 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
97,781
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- illumifin
- Normalized
- illumifin— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- illumifin.com
Disclosure history (14)newest first
- New Hampshire State AGas victim2026-04-22
illumifin Corporation, an insurance technology company, filed a supplemental notification with the New Hampshire Attorney General regarding a security incident discovered on November 4, 2025. An unauthorized individual accessed the network and exfiltrated files containing customer PII, including SSNs, driver's license numbers, financial account numbers, and medical/health insurance information. The breach affected 37 New Hampshire residents. illumifin engaged forensic investigators, notified law enforcement, and provided credit monitoring services to affected individuals. Notification letters were mailed starting March 31, 2026.
- Oregon State AGas victim2026-04-22
illumifin Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2026-04-22. The breach occurred during 10/28/2025 - 11/4/2025. The breach was discovered on 11/4/2025. 97,781 individuals were affected. Notice was sent on 4/22/2026.
- Nebraska State AGas reporting2026-04-10
illumifin Corporation, an insurance technology company and third-party administrator, notified Liberty Bankers Life Ins Co that an unauthorized person gained access to its network on November 4, 2025. The incident resulted in the exfiltration of client data, including names, addresses, and Social Security numbers. illumifin engaged a third-party forensic firm, notified law enforcement, and provided affected individuals with complimentary credit monitoring services through Epiq. Notices were sent to affected individuals around February 25, 2026.
- South Carolina State AGas victim2026-04-07
illumifin Corporation notified South Carolina residents of unauthorized network access identified on November 4, 2025. An unauthorized person accessed files containing client information, including names and addresses. The company engaged forensic investigators and notified law enforcement. Notices were sent to affected individuals on or around February 25, 2026.
- Texas State AGas victim2026-04-02
illumifin Corporation based in Woodbury, Minnesota, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-02-25 and reported on 2026-04-02. 6,724 Texas residents were affected. 41,948 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via U.S. Mail.
- Massachusetts State AGas victim2026-03-31
illumifin Corporation, an insurance technology company and third-party administrator, notified Massachusetts residents of an incident involving their personal information. The notice states that additional safeguards have been implemented to protect systems. Specific dates, attack vectors, and data types beyond general PII are not detailed in the provided letter.
- Montana State AGas victim2026-03-31
illumifin Corporation, an insurance technology company, notified Montana residents of a cybersecurity incident discovered on November 4, 2025. An unauthorized person gained access to the network and copied files containing client information. The company engaged a third-party forensic firm, contained the activity, and notified law enforcement. The specific data elements were redacted in the notification letter.
- California State AGas victim2026-03-31
On November 4, 2025, illumifin Corporation identified unusual network activity and contained unauthorized access. An investigation determined an unauthorized person accessed the network and acquired copies of files containing client information. The company engaged forensic investigators, notified law enforcement, and implemented additional safeguards. Affected individuals were notified in February 2026.
- Indiana State AGas victim2026-03-31
Illumifin Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2025-11-04 and was reported on 2026-03-31. 3,107 Indiana residents were affected. 43,152 individuals affected in total.
- New Hampshire State AGas victim2026-03-31
illumifin Corporation, an insurance technology company, notified the New Hampshire Attorney General on March 31, 2026, of a breach affecting 15 NH residents. The incident was discovered on November 4, 2025, when unauthorized access to illumifin's network resulted in the exfiltration of files containing names, SSNs, dates of birth, and health/medical information. illumifin engaged forensic investigators and law enforcement, and is offering credit monitoring to affected individuals.
- Nebraska State AGas victim2026-03-13
illumifin Corporation, an insurance technology company, notified Nebraska residents that on November 4, 2025, an unauthorized person gained access to its network and exfiltrated files containing names and Social Security numbers. Notification letters were mailed on March 13, 2026, to three Nebraska residents. illumifin offered credit monitoring and established a call center.
- MINNESOTAHHS OCRas victim2026-03-10
illumifin Corporation reported to HHS on 2026-03-10 a Hacking/IT Incident affecting 5385 individuals. Breached information located on Network Server.
- Illinois State AGas victim2026-03-01
ILLUMIFIN CORPORATION filed a data-breach notice with the Illinois Attorney General in March 2026 (case 26-03-1063). The register records the breach as discovered on February 25, 2026. Personal information types reported: medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Hawaii State AGas reporting2023-08-25
Pension Benefit Information, LLC (PBI) disclosed a data breach involving the MOVEit Transfer software vulnerability exploited by an unauthorized third party. The incident occurred May 29-30, 2023, affecting individuals whose names and other data were present on the server. PBI patched servers, investigated, and is offering credit monitoring services.