Ransomware victim disclosure
← All victimsPDCM Insurance
listed as pdcm.com · Claimed by lockbit3 · listed 1 year ago
Status timeline
- Listed
May 1, 2025
- Data leaked
At a glance
- Group
- lockbit3
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- May 1, 2025
About the victim
AI dossier — public-source company profilePDCM Insurance is a regional insurance brokerage with over 100 years of history, offering business insurance, employee benefits, personal insurance, and consulting services. Based in Waterloo, Iowa, the company serves clients across Iowa and Illinois with a team-oriented approach to risk management and insurance solutions.
- Industry
- Insurance Brokerage & Risk Management
- Address
- 3022 Airport Blvd, Waterloo, IA 50703, United States
- Employees
- 51-200
- Founded
- 1924
Attack summary
Severity: high — Insurance brokerage handles sensitive client PII, financial records, and health/benefits data at scale. Confirmed data publication by ransomware group despite lack of explicit proof count in excerpt. Regulated industry with significant compliance obligations.Lockbit3 claims to have compromised PDCM Insurance and exfiltrated data. The group's post references insurance business operations, but specific details on what data was stolen or the scope of encryption are not detailed in the available leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Client personal information
- Insurance policy records
- Employee benefits data
- Business insurance documents
- Claims information
What the group claims
We offer a range of insurance types from business and group insurance to individual life and health.
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
