Cybersecurity Awareness for Insurance Companies: Key Threats
Insurance companies hold something few other industries combine in one place: decades of medical records, financial histories, identity documents, and claims data, often on tens or hundreds of millions of people at once. That concentration has not gone unnoticed. A major cybercriminal group that spent early 2025 targeting retail corporations recently turned its full attention to insurance, using the same core technique that has worked for years: convincing a help desk employee that a locked-out account belongs to someone it does not.
This guide covers how often insurance companies are actually targeted, why the sector’s specific characteristics make it attractive to attackers, a real recent campaign that illustrates the pattern, and what insurers can do to build more effective awareness programs.
In Short
Insurance companies are increasingly targeted through social engineering rather than technical exploits, often via help desk impersonation designed to reset multi-factor authentication. Roughly 28 percent of insurance companies have experienced a breach, and a growing share of the most damaging recent attacks started with a phone call, not a phishing email.
How Often Are Insurance Companies Attacked
The scale of the problem is significant. According to Huntress’s analysis of recent cyberattacks on insurance companies, roughly 28 percent of insurance companies have experienced a breach, and 59 percent of those breaches involved a third-party attack vector rather than a direct compromise. Financial-industry firms, a category that includes insurers, reported average breach losses of roughly 6 million dollars, notably higher than the global cross-industry average.
28%
of insurance companies have experienced a breach
59%
of those breaches involved a third-party attack vector
$6M
roughly the average breach loss reported for financial-industry firms
The same research identified a consistent pattern across insurance industry breaches: phishing or credential reuse, followed by lateral movement through the network, and eventual data exfiltration, often compounded by incomplete multi-factor authentication, weak privileged access controls, and limited security visibility.
Why Insurers Are a Particularly Attractive Target
A few characteristics specific to the insurance industry make it disproportionately valuable to attackers.
The data itself is extraordinarily comprehensive.
Health insurers alone hold sensitive data on hundreds of millions of people, and auto insurers process enormous volumes of telematic driving data daily. Much of this personal data is retained for decades, far longer than a typical retail transaction record.
Legacy systems remain widespread.
A significant share of insurance firms still store client data in older systems with known, inherent security vulnerabilities, a legacy of an industry built on decades-old policy administration platforms that are expensive and disruptive to replace.
Claims systems and policy platforms concentrate data in predictable places.
Modern attacks increasingly target these systems specifically, rather than opportunistically searching for whatever is easiest to find, since claims and policy administration platforms reliably hold the highest concentration of sensitive data.
Social engineering now accounts for a substantial share of successful attacks.
Roughly one-third of documented attacks across a broad sample now begin with a social engineering tactic rather than a technical exploit, and financial and insurance sector attacks specifically show an even higher share originating from social engineering.

A Real Example: A Major Group’s Pivot to Insurance
Insurance companies are not just facing opportunistic attacks. They are increasingly the deliberate next target of established, sophisticated threat actor groups. According to reporting on the cybercriminal group Scattered Spider, the group spent the first half of 2025 targeting retail corporations before shifting its focus specifically to the insurance sector.
The technique documented in multiple incidents follows a consistent, low-tech pattern: attackers impersonate an employee who has lost their phone and been locked out of their account, contacting the company’s IT help desk directly. In documented cases, help desk staff reset multi-factor authentication settings and emailed new credentials to the attacker, effectively handing over access to the company’s systems through a single social engineering phone call rather than any technical exploit at all.
Regulatory Consequences
The regulatory consequences have followed. In New York alone, ten auto insurance providers were fined a combined total of more than 20.79 million dollars for failing to adequately protect customer data, illustrating that the financial exposure from these incidents extends well beyond the immediate cost of the breach itself.
Where AI Is Changing the Threat
Insurance-specific threat data shows AI accelerating several attack categories that particularly affect the sector. Synthetic voice fraud attacks against insurers specifically rose sharply in a recent reporting period, and AI-enhanced phishing has grown substantially across the broader financial and insurance sector, with a majority of phishing emails now incorporating some form of AI generation. This mirrors the same trend covered in our guide on pretexting, real-time, adaptive social engineering, of which the help desk impersonation pattern described above is a textbook example, and our guide on vishing simulation platforms, since voice-based social engineering is precisely how these help desk compromises succeed.
What This Means for Insurance Company Security Awareness
Help desk staff need specific, dedicated training on identity verification
Help desk staff need specific, dedicated training on identity verification, not just general phishing awareness, since the Scattered Spider pattern targets this exact function directly and repeatedly.
MFA reset procedures need a verification step
MFA reset procedures need a verification step that cannot be socially engineered over a single phone call, such as a callback to a known number or verification through a separate, previously established channel.
Third-party and vendor access deserves particular scrutiny
Third-party and vendor access deserves particular scrutiny, given that a majority of insurance industry breaches involve a third-party vector rather than a direct compromise.
Voice-based social engineering needs explicit coverage
Voice-based social engineering needs explicit coverage, not just email-based phishing awareness, given how consistently recent, high-profile incidents in this sector have started with a phone call rather than an email.
Building a Realistic Testing Program
Given how consistently recent insurance sector breaches have started with social engineering rather than a technical exploit, testing needs to reflect that reality specifically. Running a phishing test for employees that includes help-desk-style pretexting scenarios, not just email templates, gives insurers a far more accurate picture of their actual exposure than email testing alone. IT and help desk staff specifically warrant dedicated, realistic testing given how directly they have been targeted in recent, documented campaigns against the sector.
Tracking results over successive campaigns through an employee phishing risk score also helps insurers identify whether risk concentrates in specific functions, such as help desk or claims processing, information considerably more actionable than a single company-wide click rate. For insurers evaluating how this testing data factors into their own cyber insurance coverage, our guide on phishing simulation and cyber insurance covers that angle in more depth.
Final Thoughts
The insurance industry’s core business, aggregating and protecting other people’s risk and personal data, has made it a uniquely attractive target in its own right. Recent campaigns show sophisticated attackers do not need advanced technical exploits to succeed against insurers. A single convincing phone call to a help desk has proven enough. Awareness programs built around spotting a suspicious email are not built for that reality. Insurers that specifically train and test the functions attackers are actually targeting, help desks, claims processing, and privileged access, close a gap that generic phishing awareness leaves wide open.
FAQ
Why are insurance companies frequently targeted by cyberattacks?
Insurance companies hold extraordinarily comprehensive, long-retained personal data, including medical, financial, and identity information, often stored partly in legacy systems, making them a high-value target relative to the security investment many insurers have historically made.
What is the most common way attackers compromise insurance companies?
Recent high-profile incidents have followed a consistent pattern of social engineering, particularly help desk impersonation designed to trick support staff into resetting multi-factor authentication and granting account access, rather than relying on technical exploits.
How common are data breaches in the insurance industry?
Roughly 28 percent of insurance companies have experienced a breach according to recent research, with a majority of those breaches involving a third-party attack vector rather than a direct compromise of the insurer’s own systems.
What is help desk impersonation and why does it work against insurers?
Help desk impersonation involves an attacker posing as a locked-out employee to convince IT support staff to reset account credentials or multi-factor authentication. It works because help desk staff are trained to be helpful and responsive, and standard identity verification procedures are often not robust enough to catch a well-executed social engineering attempt.
How can insurance companies improve security awareness against these threats?
Effective programs go beyond general phishing training to include specific, realistic testing of help desk and claims staff against social engineering and voice-based pretexting scenarios, alongside stronger identity verification procedures for any credential or MFA reset request.
Content Reviewed By

Nawaz is a practising security analyst specializing in phishing simulation campaigns, employee awareness assessments, red team exercises, and ethical hacking. He leads phishing simulation deployments at PhishCare, a product developed by CyberSapiens, with hands-on experience evaluating and deploying phishing simulation tools across organizations in multiple industries and regions globally.
View LinkedIn ProfilePrepare Your Team for Realistic Social Engineering Threats
Recent attacks on insurers show a phone call to the help desk can be enough to cause a breach. See how realistic social engineering simulation prepares your team for it, with a free PhishCare demo account, no credit card required.







