On November 22, 2025, Healthcare & Moore, an independent insurance brokerage specializing in Medicare, health, life, and dental policies, appeared on the leak site of the dragonforce ransomware group. The company, led by Myra “Lynn” Moore, is claimed to have had internal files exfiltrated after a ransomware attack. While the exact number of affected individuals remains unknown, clients who shared personal information for insurance quotes or policy management are potentially exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
Available reporting describes the incident as a ransomware attack in which internal files were allegedly exfiltrated. The data was later published on the dragonforce leak site. Healthcare & Moore provides insurance products from more than 300 organizations and serves a client base that includes many seniors seeking Medicare and related coverage. Public reporting indicates the breach involves documents that could contain names, addresses, dates of birth, Social Security numbers, and health-insurance details. No official statement from the company had been widely reported at the time of initial publication on the leak site.
Why This Matters for You and Your Family
When an insurance broker’s files are stolen, the information inside often includes the exact details criminals need to open accounts, file fraudulent tax returns, or impersonate you with health providers. Seniors and their adult children are frequently targeted because Medicare records can be used to order expensive equipment or prescription drugs billed to government programs. If your family has ever used an independent broker for health, life, or supplemental insurance, this claimed breach could place your household in the crosshairs. The exposure of even one family member’s data can quickly affect everyone sharing the same address or phone number.
The Doxxing and Identity-Chain Implications
Ransomware groups rarely stop at publishing one set of files. Once personal records appear on a leak site, they are scraped by automated scanners and resold on multiple forums. A single email or phone number can link gaming accounts, social-media handles, and family-member profiles into a complete identity chain. Credential leaks like this one routinely cascade into account takeovers on Steam, Roblox, or other platforms used by children. Public reporting indicates that such chains allow attackers to harass victims, demand payment, or sell the full dossier to the highest bidder. The longer the data circulates unchecked, the harder it becomes to contain.