Ransomware victim disclosure
← All victimsAmerican Plan Administrators
listed as apatpa.com · Claimed by Lockbit5 · listed 2 days ago
Status timeline
- ListedAug 29, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileAmerican Plan Administrators is a third-party healthcare administrator offering self-funded health plan solutions for employee groups of various sizes. Based in Maryland, the company provides plan administration, network solutions, risk management, and compliance services with 30+ years of operating experience.
- Industry
- Healthcare Administration & Third-Party Benefits Management
- Address
- PO Box 477, Arnold, MD 21012
Attack summary
Severity: critical — Third-party healthcare administrator handling sensitive protected health information (PHI), employee personal data, and health plan records for multiple client organizations. Breach affects not just the administrator but downstream exposure of regulated healthcare data at scale.LockBit5 claims to have accessed American Plan Administrators' systems and published exfiltrated data. The group has disclosed the attack on their leak site, indicating data exfiltration occurred.
Data the group says was taken
AI dossier — extracted from the leak post- Health plan administration records
- Employer client data
- Member/employee health information
- Plan design and utilization details
What the group claims
American Plan Administrators offers smart self-funded healthcare solutions designed to maximize savi...
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

