Ransomware victim disclosure
← All victimsHoneycomb Insurance
listed as Honeycomb Programs Inc · Claimed by Direwolf · listed 3 days ago
Status timeline
- ListedSep 1, 2026
- Data leakeddate unknown
At a glance
- Group
- Direwolf
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Sep 1, 2026
About the victim
AI dossier — public-source company profileHoneycomb Insurance is a digital real estate insurance platform specializing in coverage for condominiums, homeowner associations (HOAs), building owners, property managers, and developers. The company offers instant quotes, online policy management, and customizable coverage with AI-powered property inspection technology.
- Industry
- Insurance & Real Estate
Attack summary
Severity: critical — Confirmed exfiltration of massive scale personal identifiable information (379,000+ user accounts with names, emails, addresses, phone numbers), financial data (payment records, commissions, policy premiums, bank information), tax identification numbers, and regulated insurance policy data affecting tens of thousands of customers. Additionally includes SSN fields in compliance/sanctions lists and comprehensive audit trails. This represents comprehensive compromise of a financial services platforThe direwolf group claims to have exfiltrated Honeycomb's complete data warehouse, including 22 MongoDB databases with approximately 79.55 million documents and 1.15 TB of policy, quote, and letter documents stored in object storage. The group published a detailed inventory of the breached data showing customer PII, policy records, payment information, and IVANS transaction records.
Data the group says was taken
AI dossier — extracted from the leak post- User accounts (379,000 records with names, emails, phone, addresses, commissions)
- Customer entities (54,000 records)
- Insurance quotes (632,000+ records with address, bank, income, email, phone)
- Policies and master policies (106,580 records with address, income, phone, email, premium)
- Master proposals (87,500 records with address, email, tax ID)
- Payment records (311,000+ records)
- Claims data (2,473 records)
- Invoices (115,000 records)
- Commissions (23,000 records)
- Property data extracts (785,000 records)
- Audit logs (7.48+ million records)
- SDN sanctions lists including SSN fields
- IVANS transaction records (245,000 records)
- Policy, quote, and letter documents (1,237,966 objects, 1.15 TB)
What the group claims
Insurance
The leak post
captured from the group's site```
{"article":{"id":116,"title":"Honeycomb Programs Inc","content":"\u003ch1\u003eData Warehouse Briefing\u003c/h1\u003e\n\u003ch2\u003e1. Overview\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eItem\u003c/th\u003e\n\u003cth\u003eValue\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eBusiness\u003c/td\u003e\n\u003ctd\u003e\u003cstrong\u003eHoneycomb Insurance\u003c/strong\u003e — insurance platform (quoting, policies, claims, premiums, commissions, IVANS transaction integration; includes user/customer portal and document storage)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eTotal size\u003c/td\u003e\n\u003ctd\u003eMongoDB: \u003cstrong\u003e22 databases / 396 collections\u003c/strong\u003e, approximately \u003cstrong\u003e79.55 million documents\u003c/strong\u003e; plus an object-storage bucket with \u003cstrong\u003e1,237,966 objects, approximately 1.15 TB (1,048 TiB)\u003c/strong\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2\u003e2. Database Inventory\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u0…Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

