Ransomware victim disclosure
← All victimsYoung Consulting
Claimed by Blacksuit · listed 2 years ago
Status timeline
- ListedMay 7, 2024
- Data leakeddate unknown
At a glance
- Group
- Blacksuit
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- May 7, 2024
About the victim
AI dossier — public-source company profileYoung Consulting is a software provider specializing in solutions for the employer stop-loss insurance market. They develop integrated platforms (ESLOffice, BenefitConnect, Claimpointe, Xchangecentre) used by carriers, brokers, and third-party administrators for underwriting, administration, and claims management of medical stop-loss and group term life insurance.
- Industry
- Software & Insurance Technology
- Address
- 180 Interstate North Parkway SE Suite 400, Atlanta, GA 30339
Attack summary
Severity: high — Confirmed data publication by ransomware operator; victim is a critical software provider in the insurance supply chain handling sensitive underwriting, claims, and financial data for multiple carriers and administrators. Risk of widespread downstream exposure.Blacksuit claims to have attacked Young Consulting. The leak post provides no details on what data was exfiltrated or whether systems were encrypted; disclosure status indicates data has been published.
Data the group says was taken
AI dossier — extracted from the leak post- stop-loss insurance records
- underwriting data
- claim information
- carrier/broker communications
- third-party administrator data
What the group claims
Young Consulting is the market leader in providing software solutions to the employer stop loss marketplace.
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

