Ransomware victim disclosure
← All victimsGGI Tokio Marine / GGI Pins Insurance
listed as GGI · Claimed by morpheus · listed 30 days ago
Status timeline
- Listed
Apr 21, 2026
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileGGI operates two insurance brands — ggitokiomarine.com and ggipinsurance.com — providing comprehensive general and life insurance solutions in Japan, including motor, fire, marine, and specialized insurance products. The group reports annual revenue of approximately $19.2 million. The entity appears to be a mid-sized regional insurer operating under or affiliated with the Tokio Marine brand.
- Industry
- Insurance (General & Life)
Attack summary
Severity: critical — An insurance company breach with confirmed data publication is highly likely to involve regulated PII at scale (policyholder names, addresses, financial details, health/life insurance data), meeting the threshold for critical severity under applicable financial and privacy regulations.The Morpheus ransomware group claims to have compromised GGI and published data from the victim, indicating confirmed exfiltration. The leak post discloses the attack under a 'data_published' status, suggesting sensitive company and potentially policyholder data has been released.
Data the group says was taken
AI dossier — extracted from the leak post- Insurance policy records
- Customer personal information
- Financial records
- Business documents
What the group claims
**Website**: ggitokiomarine.com **Website**: ggipinsurance.com **Revenue**: $19.2 Million Provides comprehensive general and life insurance solutions, including motor, fire, marine, and specialized
Source
Indexed 30 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
