CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back 🛡 Active Threats Mar 26, 2026

Beacon Mutual hit by ransomware attack - Rhode Island Current

Rhode Island Current Archived Mar 26, 2026 ✓ Full text saved

Beacon Mutual hit by ransomware attack Rhode Island Current

Full text archived locally
✦ AI Summary · Claude Sonnet


    TECHNOLOGY Beacon Mutual hit by ransomware attack Warwick-based workers’ compensation insurance company says its live systems remain safe from harm BY: ALEXANDER CASTRO - FEBRUARY 5, 2026 8:18 PM A laptop screen displays the homepage for Beacon Mutual Insurance Company. (Photo by Alexander Castro/Rhode Island Current) A state vendor and major provider of workers’ compensation insurance in Rhode Island confirmed it was the victim of a cyberattack in January.    The Beacon Mutual Insurance Company posted about the Jan. 14 incident to its website around noon Thursday, following inquiries from Rhode Island Current earlier in the day. The requests for comment were prompted by Beacon’s appearance on public websites that list and track recent reports of ransomware — a genre of malware characterized by making users’ files encrypted and inaccessible unless they pay a price. “Yes, this was a ransomware attack,” Michelle N. Pelletier, the assistant vice president of marketing and communications at the Warwick company, confirmed over email late Thursday afternoon. But Pelletier added that not all was lost, and that the company’s production environment — or the live systems that users interact with directly — remained safe from harm.   “Fortunately, our production environment was not encrypted, and we were able to resume normal operations on January 20,” Pelletier wrote.    Pelletier added that the company is “working with experts on a complete forensic analysis of the potential data affected by the incident,” and that any people whose personal information may have been stolen or affected as part of the breach will be notified.   “To ensure the integrity of the ongoing investigation, we are not able to provide additional details at this time,” Pelletier said.  The Warwick-based company’s Thursday afternoon account of what happened did not provide details of the “unauthorized access to our systems.” This suspicious activity was first observed on Jan. 14, and select systems on the company’s network were “proactively disconnected” to stop the threat’s further progression. The company’s statement adds that it then began a forensic investigation and notified law enforcement.   “Beacon Mutual’s response to this incident has been guided by our mission to provide outstanding service and our values to do the right thing and empower employers to succeed by caring for the safety, well-being, and security of their employees​​​​​,” the statement read.  Beacon is designated as the state’s third party administrator for state employees’ workers’ compensation claims, according to a state employee handbook published in November 2025.  The company is also considered the state’s “insurer of last resort,” meaning it is required to provide workers’ compensation coverage to employers who cannot find a willing insurer in the voluntary market, who may decline to provide coverage as particular employers may be considered too big a risk.  The Rhode Island Department of Labor and Training, which handles workers’ comp, referred comment to the Department of Administration, which did not respond to requests for comment as of early Thursday evening.  According to Rhode Island’s transparency portal, in fiscal year 2025 the state spent $23,209,038 on services rendered by Beacon across 402 transactions in total, although the portal does not provide many specifics as to these payments.   The initial rumblings of a class action lawsuit have already emerged online: The Washington, D.C.-based firm Mason LLP posted to its website Wednesday that it is “investigating a class action lawsuit for the victims of the recent breach at Beacon Mutual Insurance.” The firm did not respond to requests for comment Thursday.  Hacker group claims responsibility Beacon’s Thursday statement noted that the company, like any organization, “operates within a dynamic threat environment in which security risks may arise despite reasonable and appropriate safeguards.” The insurer maintains that it has a “comprehensive information security program” with multiple and industry-standard safeguards in place. On the other end of the equation is the threat actor taking credit for the breach: INC Ransom, which posted to its dark web site around Jan. 29 that it had pilfered 275 GB of “highly sensitive internal data,” according to screencaps of the leak site ransom page posted by ransomware tracking sites.  To ensure the integrity of the ongoing investigation, we are not able to provide additional details at this time. – Michelle N. Pelletier, assistant vice president of marketing and communications for Beacon Mutual Connor Goodwolf — a Columbus, Ohio-based cybersecurity researcher who researches and reviews the data breach claims by cybercriminals — confirmed Thursday that the ransom page for Beacon Mutual remains live on the INC Ransom’s site. Screencaps posted to the site and reviewed by Goodwolf show the criminals claiming a bounty of internal corporate documents, financial reports, employees’ and claimants’ personal information, Social Security numbers, NDAs, a database of clients and policyholders, and system backups.  Goodwolf said over text message Thursday that, on some leak posts, INC includes a countdown or indicator of when files will be publicly released, and that it “looks like they drop files after 14 or so days after releasing a post.” The leak page for Beacon, however, lacks a timer, Goodwolf said.  A November 2025 report from Blackpoint Cyber, a Denver-based cybersecurity firm, traces INC’s first appearance to 2023, and notes that the group’s alleged ransom efforts have mostly been based in North America. INC is believed to operate as “ransomware as a service.” This business model is a criminal mirror of the “software as a service” model, which includes popular apps like Zoom, Canvas, Slack, Airtable, Dropbox — essentially, software stored on a company’s servers and accessed via the cloud by users. In the ransomware variant, other cybercriminals known as affiliates are able to enlist the service operators to carry out an attack, allowing less technically savvy criminals access to heavier-duty techniques. Goodwolf pointed out over text that INC has a track record for high-profile targets, including the Pennsylvania AG’s office and Stark Aerospace, a U.S. Department of Defense contractor. Both breaches happened in 2025 and were confirmed by public officials. According to Blackpoint, INC Ransom has been observed to use the double extortion method, which often starts with a traditional ransomware attack: Files on a victim’s network are encrypted, and then criminals demand payment from victims so their now-unusable files can be restored. The second blow in a double extortion attack is data exfiltration. Criminals steal data from a victim’s servers, then threaten to post the data online unless paid a sum, usually an exorbitant one.  INC’s ransomware uses file size to guide its partial encryption method, combining that tactic with a “multithreading” approach to make its encryption even speedier, according to Blackpoint. The ransomware leaves ransom notes in each encrypted directory, and can also summon these notes into the physical world.  “INC Ransom actively seeks out available printers in the network and sends the command to print the ransom note,” the report reads, adding that the malicious software might also replace a machine’s desktop wallpaper with the ransom note. The Blackpoint researchers wrote that INC Ransom became much more active in 2025. When the report was published in November 2025, the criminal outfit had claimed 300 victims so far that year, compared to 162 victims in 2024.  “The increase in activity and their ability to remain a credible threat in the ransomware landscape has been attributed to their ability to adapt,” the report reads. Company stabilized insurance market in 1990s Mutual insurance companies are collectively owned by their policyholders, rather than outside shareholders, and each policyholder comprises a member of the company — which also makes them eligible for dividends, of which Beacon paid out about $6 million in 2024, according to a routine report conducted by the Rhode Island Department of Business Regulation’s Insurance Division. The report, which examined the years 2020 up through 2024, recaps the company’s past and present, a history also iterated on Beacon’s own website. Before it was Beacon, the company was known as the State Compensation Insurance Fund — a product of 1990 legislation by the Rhode Island General Assembly which sought to stabilize the state’s workers’ compensation system amid an exodus of private insurers a decade earlier.   The creation of the State Compensation Insurance Fund — which officially became Beacon in 1992 — helped soothe bedlam in the workers’ comp market, along with additional reforms by the legislature. By the mid-1990s, the workers’ comp system had recovered, and Beacon, a private company, was able to pay back the $5 million the state had loaned in its creation.  Over time, Beacon amended its company charter and expanded its licensing authority to operate beyond Rhode Island, and it now operates in Massachusetts and Connecticut through partnerships with other companies. GET THE MORNING HEADLINES. SUBSCRIBE REPUBLISH Our stories may be republished online or in print under Creative Commons license CC BY-NC-ND 4.0. We ask that you edit only for style or to shorten, provide proper attribution and link to our website. AP and Getty images may not be republished. Please see our republishing guidelines for use of any other photos and graphics. ALEXANDER CASTRO Alexander Castro covers education, health and technology for Rhode Island Current. He previously worked as a visual arts critic, curator and adjunct professor. Rhode Island Current is part of States Newsroom, the nation’s largest state-focused nonprofit news organization. MORE FROM AUTHOR MORE FROM OUR NEWSROOM Hackers sit on RIBridges data dump BY ALEXANDER CASTRO December 21, 2024 Lawmakers consider bill that would keep private keys private in Rhode Island BY ALEXANDER CASTRO March 9, 2026 Temporarily banning data centers draws more interest from state, local officials BY MADYSON FITZGERALD March 8, 2026
    💬 Team Notes
    Article Info
    Source
    Rhode Island Current
    Category
    🛡 Active Threats
    Published
    Mar 26, 2026
    Archived
    Mar 26, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗