Group 1001 Insurance Units Resume Full Operations after Ransomware Attack
Incident Overview
- Beginning on
February 9, 2023 , we were alerted to the existence of sophisticated ransomware on our information technology infrastructure. - We immediately launched an investigation to determine the full scope of the incident, and a team of third-party forensic experts was engaged to assist in the investigation, which is ongoing.
- Based on our investigation to date, our forensic experts have confirmed that the ransomware code deployed in our environment has been contained and will not spread to any other internal or external systems.
- We have alerted the FBI and will continue to provide information regarding the incident as they investigate.
- We did not pay a ransom.
Containment & Remediation
- We took immediate action by proactively disconnecting systems from our network to contain the threat and prevent additional systems from being affected.
- Along with our forensics experts, our team scanned systems for indicators of compromise and remediated any identified indicators of compromise.
- In addition, we deployed additional advanced endpoint detection and monitoring tools on our newly restored systems for an added layer of security and visibility across our network.
- All systems were validated as clean by conducting additional scans before they were brought back online.
- We have been, and continue to be, in communication with our regulators about this incident.
- There will be a number of other infrastructure enhancements to continuously strengthen the security posture of Group 1001's network and systems in the days, months, and years ahead.
Restoration
- While our investigation is ongoing, we are confident that the attack has now been successfully contained.
- We have fully resumed normal operations.
- The security of our information and that of our contract holders and other stakeholders is important to us. Once our investigation is complete, we will notify any impacted parties as appropriate.
We want to confirm that it is safe to conduct business with us and to communicate with us via e-mail, our website portals, and our call centers. We apologize for any inconvenience and genuinely appreciate your patience and understanding as we worked vigorously to fully restore our computer networks.
For further questions about this incident, please e-mail our incident response team at: [email protected]
View original content to download multimedia:https://www.prnewswire.com/news-releases/group-1001-insurance-units-resume-full-operations-after-ransomware-attack-301758740.html
SOURCE Group 1001
G2’s Lauren Erickson Named 2023 Nonprofit Power Broker
AXA XL continues build out of US Mid-Market insurance team
Advisor News
Annuity News
Health/Employee Benefits News
Life Insurance News