On October 25, 2024, IDN was listed on the leak site operated by the qilin ransomware group. The company, which began in the early 1970s as a family-oriented estate planning and insurance business, is claimed to have had internal files exfiltrated during a ransomware attack. The leak-site listing does not specify the number of people affected or detail exactly which records were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch IDN
Get alerted the next time IDN files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about IDN’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Qilin Listing
The primary disclosure on the qilin leak site states that IDN suffered a ransomware incident in which attackers successfully exfiltrated internal files. No victim count, ransom amount, or specific data categories such as customer names, policy numbers, or financial details are provided in the listing. The disclosure indicates the data is now published for anyone who visits the onion site, following IDN’s apparent failure to meet the group’s demands. Public reporting on similar qilin postings shows that once files appear on the leak site they remain available for download, increasing long-term exposure risk.
Why This Matters for You and Your Family
If you or your family purchased life insurance, estate-planning services, or related financial products from IDN, your personal information may now sit in an attacker-controlled archive. Internal files exfiltrated in ransomware cases frequently contain names, addresses, dates of birth, Social Security numbers, policy documents, and beneficiary details. Even without an exact count, the exposure creates immediate identity-theft and fraud risk for ordinary customers who trusted the company with sensitive life-event paperwork. Families who arranged coverage for children, spouses, or aging parents face compounded consequences when those records surface in criminal forums.
Doxxing and Identity-Chain Risks
Leaked internal files rarely stay isolated. Attackers and subsequent buyers routinely cross-reference names, addresses, and phone numbers with other breach data to build complete identity profiles. A single policy document can link your email address to your children’s names, schools, or even gaming usernames. These connections allow doxxing chains that lead to account takeovers on social media, email, and gaming platforms. Credential leaks of this nature often cascade into harassment, SIM-swapping, or targeted fraud against entire households. October 25, 2024 marks the moment this particular dataset became publicly available to any motivated actor.