On September 25, 2025, the Akira ransomware group listed Milliman Financial Risk Management LLC on its leak site and announced plans to publish 260 GB of stolen corporate data. The affected company, a subsidiary of Milliman, Inc., provides financial risk management services to the retirement savings industry and operates trading platforms in Chicago, London, and Sydney. Public reporting indicates the exposed material includes client financial portfolios, account balances, transfers, internal operating files, financial and accounting records, contracts, agreements, and project documents.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Milliman Financial Risk Management LLC
Get alerted the next time Milliman Financial Risk Management LLC files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Milliman Financial Risk Management LLC’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Available reporting describes the incident as a ransomware attack in which Akira exfiltrated data before encrypting systems or demanding payment. The group has not yet uploaded the full archive but has posted a sample and stated it will release the remaining 260 GB soon. No exact number of individuals whose information appears in the files has been disclosed. The breach affects clients of Milliman Financial Risk Management LLC whose portfolios, balances, and related financial records were stored in the compromised systems.
Why This Matters for You and Your Family
When a financial services firm loses control of client portfolios and account details, the information can be used to impersonate you, file fraudulent tax returns, open new accounts in your name, or pressure you with extortion demands. Client financial portfolios and account balances are especially valuable because they reveal net worth, investment holdings, and banking relationships. If you or any member of your family has retirement accounts, pensions, or advisory services connected to Milliman or its clients, your personal financial data may now sit on a ransomware leak site. Even if your name is not publicly listed today, the files could surface weeks or months later.
The Doxxing and Identity-Chain Risks
Financial records rarely exist in isolation. A single leaked email, phone number, or client ID can be chained with other breaches to map your full digital footprint. Attackers link your work email to personal accounts, then to social media handles, then to family members. This identity chain often leads to doxxing, targeted phishing, or account takeovers. Credential leaks like this one frequently cascade into gaming platforms, where children’s accounts become entry points for further harassment or extortion. Once the data reaches underground forums, it can be repackaged and sold repeatedly.