Ransomware victim disclosure
← All victimsCharles River Insurance
Claimed by Akira · listed 2 months ago
Status timeline
- ListedApr 3, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Apr 3, 2026
About the victim
AI dossier — public-source company profileCharles River Insurance is an independent insurance agency headquartered in Massachusetts. The firm focuses on delivering personalized risk management and insurance solutions to both individuals and businesses.
- Industry
- Independent Insurance Agency
- Address
- Massachusetts, United States
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII at scale including SSNs, passport data, driver's licenses, and financial/payment details for both individual and business customers of an insurance agency — a classic critical-severity profile under privacy and financial data regulations.Akira claims to have exfiltrated approximately 63 GB of corporate data, including detailed employee and customer personal information (passports, driver's licenses, SSNs, addresses, phone numbers, emails), financial records, payment details, and project documentation, with publication described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Passport documents
- Driver's licenses
- Social Security Numbers (SSNs)
- Customer and employee addresses
- Phone numbers and email addresses
- Financial records
- Payment details
- Project documentation
What the group claims
Charles River Insurance is an independent insurance agency headqu artered in the state of Massachusetts that focuses on delivering personalized risk management and insurance solutions to individua ls and businesses. We will upload 63gb of corporate data soon. Detailed employee and customer personal information (passport, DLs, SSNs, addresses, p hones, emails and so on), detailed financials, payment details, p rojects, etc.
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

