Ransomware victim disclosure
← All victimsKemper Corporation
Claimed by shinyhunters · listed 1 month ago
Status timeline
- Listed
Apr 12, 2026
- Data leaked
At a glance
- Group
- shinyhunters
- Status
- Data leaked
- Country
- US
- Sector
- Financial Services
- Listed on leak site
- Apr 12, 2026
About the victim
AI dossier — public-source company profileKemper Corporation is a Chicago-based insurance holding company offering personal and commercial insurance products across the United States. The company operates through multiple subsidiaries providing auto, home, life, and specialty insurance. Kemper serves millions of policyholders and is publicly traded on the NYSE.
- Industry
- Insurance & Diversified Financial Services
- Address
- One E. Wacker Drive, Chicago, IL 60601, USA
- Employees
- 5000-10000
- Founded
- 1912
Attack summary
Severity: critical — Claimed exfiltration of over 13 million records containing PII from a regulated insurance/financial services company constitutes a large-scale breach of sensitive consumer data subject to financial and privacy regulations (e.g., GLBA, state insurance data laws).ShinyHunters claims to have exfiltrated over 13 million Salesforce records containing personally identifiable information and internal corporate data, issuing a final ransom ultimatum with a deadline of 14 April 2026 before public release.
Data the group says was taken
AI dossier — extracted from the leak post- Salesforce CRM records
- Personally identifiable information (PII)
- Internal corporate data
What the group claims
Over 13M Salesforce records containing PII and other internal corporate data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK
Source
Indexed 1 month agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
