Ransomware victim disclosure
← All victimsMinnesota Health Insurance Network
listed as MN Health Insurance Network · Claimed by Akira · listed 2 months ago
Status timeline
- ListedApr 9, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Apr 9, 2026
About the victim
AI dossier — public-source company profileMinnesota Health Insurance Network is a US-based health insurance provider operating in Minnesota. The company offers a wide range of health insurance products including individual and family plans, group and small business plans, Medicare plans, dental and vision insurance, and short-term health insurance. No public website was available to confirm additional operational details or scale.
- Industry
- Health Insurance Brokerage & Plans
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII at scale from a healthcare/insurance entity, including passport data, personal contact information, and financial records for both clients and employees — squarely within regulated sensitive data categories (HIPAA-adjacent, financial PII).Akira claims to have exfiltrated approximately 23 GB of corporate data, including client and employee personal information (passports, addresses, phone numbers, emails), project files, financial records, and contracts and agreements, with publication of the data imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Client personal information (passports, addresses, phones, emails)
- Employee personal information (passports, addresses, phones, emails)
- Financial records
- Contracts and agreements
- Project files
What the group claims
Minnesota Health Insurance Network specializes in providing a wid e range of health insurance products, including individual and fa mily plans, group and small business plans, Medicare plans, denta l and vision insurance, and short-term health insurance. We will upload 23gb of corporate data soon. Client and employee p ersonal information (passports, addresses, phones, emails and so on), projects, financials, contracts and agreements and so on.
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

