> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# International Insurer VUMI Group Allegedly Breached, 300K Policyholders and 25K Staff Exposed With SSNs, Passports, and W-9 Forms
- URL: https://darkwebinformer.com/international-insurer-vumi-group-allegedly-breached-300k-policyholders-and-25k-staff-exposed-with-ssns-passports-and-w-9-forms/
- Published: 2026-04-13T17:35:20.000Z
- Updated: 2026-04-13T17:35:20.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Dark Web Informer - Cyber Threat Intelligence 

# International Insurer VUMI Group Allegedly Breached, 300K Policyholders and 25K Staff Exposed With SSNs, Passports, and W-9 Forms

April 13, 2026 - 2:12:51 PM UTC 

United States 

Insurance 

Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. 

[ View API](https://darkwebinformer.com/api-details/) 

 Unlock Exclusive Cyber Threat Intelligence

Powered by DarkWebInformer.com

Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously.

[ Subscribe Now](https://darkwebinformer.com/pricing) 

## Quick Facts

Date & Time 2026-04-13 14:12:51 UTC 

Threat Actor bytetobreach 

Victim VUMI Group International Insurance 

Industry Insurance 

Category Data Breach 

Insured Clients \~300,000 

Staff / Partners / Agents 25,000+ 

Exfiltration Duration 6 Days 

Severity Critical 

Price Contact Seller 

Network Open Web 

Country United States 

##  Incident Overview

A threat actor going by bytetobreach claims to have breached VUMI Group, an international health and life insurance provider. VUMI Group operates globally and provides coverage to expatriates, multinational organizations, and high-net-worth individuals. The actor states the exfiltration took 6 days using carefully calibrated parameters to avoid crashing the server, and emphasizes that all databases and documents were taken exclusively from VUMI Group with no third-party involvement.

  
The breach reportedly exposes approximately 300,000 insured clients and over 25,000 staff, partners, and agents. The actor describes the dataset as containing "everything" and specifically highlights the following:

- **Complete PII**: Full personally identifiable information for both agents and clients.
- **Social Security Numbers**: SSNs for affected individuals, confirmed by a dedicated proof screenshot (5\_SSN\_NUMBERS.png).
- **Passport Documents**: Scanned passport documents for policyholders, confirmed by a separate proof screenshot (6\_PASSPORT.png).
- **W-9 Tax Forms**: U.S. tax forms containing taxpayer identification numbers, legal names, addresses, and certification signatures.
  
The actor provided a methodical series of proof screenshots documenting the attack chain: 1\_POSSIBLE\_VULNERABILITY.png (initial vulnerability discovery), 2\_PAYLOAD.png (exploit delivery), 3\_DB\_ENUM.png (database enumeration), 4\_EXFILTRATION.png (data extraction), 5\_SSN\_NUMBERS.png (SSN data proof), and 6\_PASSPORT.png (passport document proof). This structured proof format suggests a deliberate, documented attack rather than an opportunistic data grab.

  
The data is being distributed through OwnCloud with two backup links, and the actor prefers contact via Session or Signal messaging. Given that VUMI Group serves expatriates and international clients, the combination of SSNs, passport scans, and W-9 forms creates an exceptionally high identity theft risk. Passport documents in particular enable travel document fraud, while W-9 forms provide the exact information needed for tax identity theft.

##  Compromised Data Categories

 Social Security Numbers  Passport Documents (Scans)  W-9 Tax Forms  Complete PII (Clients & Agents)  Insurance Policy Data  Staff & Partner Records  Agent Network Data  Database Contents 

##  Image Preview

[![Forum post by bytetobreach showing VUMI Group International Insurance logo and initial vulnerability proof screenshot](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9237895692783659872365987236598722.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9237895692783659872365987236598722.png) [![Attack chain proof screenshots, 300K insured and 25K staff exposure details, OwnCloud download links, and Session/Signal contact preferences](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9237895692783659872365987236598723.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/04/9237895692783659872365987236598723.png) 

##  Claim URL

Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. 

[ Subscribe](https://darkwebinformer.com/pricing) 

Subscriber Access View the original listing URL and unredacted claim images on the feeds below. 

[ Threat Feed](https://darkwebinformer.com/threat-feed/) [ Ransomware Feed](https://darkwebinformer.com/ransomware-feed) 

##  MITRE ATT&CK Mapping

[ T1190 Exploit Public-Facing Application The documented attack chain shows vulnerability discovery followed by payload delivery against VUMI Group's web-facing infrastructure to gain initial access to the insurance database. ](https://attack.mitre.org/techniques/T1190/) [ T1213 Data from Information Repositories Database enumeration followed by systematic extraction of policyholder records, agent data, SSNs, passport documents, and W-9 forms from VUMI Group's insurance management systems. ](https://attack.mitre.org/techniques/T1213/) [ T1589.001 Gather Victim Identity: Credentials Harvests SSNs, passport data, and W-9 tax forms for 300,000 insured clients and 25,000+ staff/agents, creating a comprehensive identity theft and tax fraud dataset. ](https://attack.mitre.org/techniques/T1589/001/) [ T1030 Data Transfer Size Limits The actor explicitly used throttled extraction parameters over 6 days to avoid crashing the server, indicating careful data transfer size management during the exfiltration. ](https://attack.mitre.org/techniques/T1030/) [ T1567 Exfiltration Over Web Service Distributes the stolen insurance data through OwnCloud with two backup download links, with the actor preferring Session and Signal for buyer communications. ](https://attack.mitre.org/techniques/T1567/) [ T1005 Data from Local System Collects scanned passport documents and W-9 tax forms stored on the insurance company's file systems, representing document-level data beyond structured database records. ](https://attack.mitre.org/techniques/T1005/) 

Dark Web Informer © 2026 | Cyber Threat Intelligence  
[DarkWebInformer.com](https://darkwebinformer.com/)