Last updated 1 month ago
Kemper Corporation, an American insurance holding company, suffered a data breach disclosed in April 2026 after the ShinyHunters ransomware group claimed responsibility. The incident exposed 269,299 unique email addresses along with associated personal and financial data. The breach was part of a broader extortion campaign targeting hundreds of organizations using the same method.
The attackers gained initial access to Kemper's Salesforce environment through social engineering, bypassing authentication controls. They exfiltrated tens of gigabytes of data including internal directory records, Salesforce records, and Stripe payment logs. The exposed data comprised names, phone numbers, physical addresses, and partial payment card information (last 4 digits, expiry dates, and card brands). ShinyHunters published the stolen data after Kemper did not meet the ransom demand.
Kemper confirmed the incident and engaged third-party cybersecurity experts while notifying law enforcement. No further details on regulatory actions, litigation, or ransom payment were disclosed.
Social engineering of Salesforce environment as part of a broader campaign
Kemper's reliance on Salesforce without adequate social engineering defenses allowed attackers to compromise a critical customer-facing system. The exposure of payment card data, even partial, indicates insufficient data segmentation and encryption within the Salesforce environment. Organizations handling sensitive financial data should implement multi-factor authentication and strict access controls for third-party platforms, and regularly audit data storage to minimize the blast radius of a single-vector compromise.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor