Skip to content

Family First Life Dataset Claim Includes Agent Credentials, Client PII and Banking Data

Breach Report United States Insurance, PII & Financial Data $1.2B Premium

Family First Life Dataset Claim Includes Agent Credentials, Client PII and Banking Data

A forum actor posting as FFLDarkPacket is offering what they claim is a database belonging to Family First Life (FFL), covering a stated period from 2014 through September 2026. The listing claims the material includes full agent credentials and agent numbers by insurance carrier, as well as client records containing insured names, addresses, dates of birth, phone numbers, email addresses and policy details. The actor also claims the dataset contains SSNs, HIPAA-related information, banking information, several million leads, policy extracts and other records. Carriers named in the post include American Amicable, Americo, Mutual of Omaha and Transamerica. The listing advertises an aggregate $1.2 billion in premium and says payment is accepted in Bitcoin, USDT or Monero. The claim is unverified.

Sponsored
Period2014-2026
Premium$1.2B
LeadsMillions
Carriers named4

Post details

TargetFamily First Life
CountryUnited States
SectorInsurance
ListingDatabase leak / sale
Claimed period2014 - Sep 2026
Premium represented$1.2B
Observed
ActorFFLDarkPacket

!What the post claims

  • Family First Life source data
  • Coverage from 2014 through September 2026
  • Full agent credentials
  • Agent numbers by carrier
  • Insured names
  • Home addresses
  • Dates of birth
  • Phone numbers
  • Email addresses
  • Policy details
  • SSNs
  • HIPAA-related information
  • Banking information
  • Several million leads
  • Policy extracts
  • American Amicable records
  • Americo records
  • Mutual of Omaha records
  • Transamerica records
  • $1.2B aggregate premium claimed
  • Multi-billion-dollar coverage claimed
  • Bitcoin, USDT or Monero accepted

Screenshot

Forum post claiming a Family First Life dataset containing insurance agent, client, policy, banking and identity information, observed 18 September 2026.

Mapped techniques

The actor attributes the breach to a bounty program but does not describe a technical intrusion method. The technique below is inferred only from the type of structured insurance and customer information advertised.

  • Collection T1213 Data from Information Repositories Inferred The alleged material combines agent, policyholder, banking, lead and policy information in a relational dataset, which is consistent with collection from internal information repositories or business applications.

Potential impact

If authentic, the dataset could expose agents and insured customers to identity theft, financial fraud, insurance fraud, credential abuse and highly targeted social engineering. The combination of names, dates of birth, addresses, phone numbers, email addresses, policy details, claimed SSNs and banking information would create a particularly sensitive identity profile. Agent credentials and carrier-specific identifiers could also be abused to impersonate insurance professionals or access related systems if any credentials remain valid. The breadth of the claimed dataset and its multi-year coverage could increase the value of the material for fraud and account takeover attempts.

iStatus Unverified

The forum post lists specific categories of agent and customer data, names several insurance carriers and provides a visible sample presented as evidence. The actor also claims the dataset is relational and internally consistent. However, the post does not provide an independently verifiable technical account of how the data was obtained, and Dark Web Informer has not independently verified the authenticity, completeness, source or stated $1.2 billion premium value of the alleged Family First Life dataset.

Dark Web Informer // Threat Intelligence

Latest