Landmark Admin, LLC, a third-party administrator that handles policy records on behalf of insurance carriers, has notified individuals that intruders broke into its network, encrypted files, and took data out of the system before being discovered. Landmark says it first spotted suspicious activity on May 13, 2024, and its forensic review later determined the unauthorized activity ran through June 17, 2024, with the investigation itself wrapping up on July 24, 2024. That timeline — encryption paired with data being copied off the network — is the pattern typically seen in a ransomware attack, and Landmark states it disconnected affected systems, brought in outside cybersecurity specialists, and notified law enforcement once the intrusion was confirmed.
Because Landmark administers policies for multiple insurance carriers, the people receiving this letter are current or former policyholders, insureds, or others named on an insurance policy that Landmark processed. The company says it is still working through its systems to identify everyone impacted and is mailing letters on a rolling basis as it confirms names, which is why some recipients may hear about this later than others.
What personal information did Landmark say was accessed?
- The letter states that the information involved varies from person to person, and the specific data elements are filled in individually rather than listed in the general notice language.
- Landmark is offering credit monitoring, CyberScan dark web-style monitoring, and identity theft recovery services — the kind of protection typically extended when sensitive identifiers such as Social Security numbers or financial account details may be part of what was taken.
- If your own letter names specific data types (for example a Social Security number, driver’s license number, or financial account information), treat those as confirmed and follow the steps below accordingly.
Landmark is offering free identity theft protection services through IDX, A ZeroFox Company, which include either 12 or 24 months of credit and CyberScan monitoring (the length varies by individual), a $1,000,000 insurance reimbursement policy, and fully managed identity theft recovery support. You can enroll at https://response.idx.us/landmark using the enrollment code printed in your individual letter, or by calling 1-866-273-9228 (Monday through Friday, 9:00 a.m. to 9:00 p.m. Eastern). The stated deadline to enroll is April 24, 2025, so it’s worth acting before that date rather than setting the letter aside.
Steps to take if your name was on this list
- Enroll in the free IDX monitoring before the April 24, 2025 deadline, since it includes recovery help you’d otherwise have to arrange yourself.
- Place a security freeze with Experian, Equifax, and TransUnion individually — this blocks new accounts from being opened in your name without your consent and costs nothing.
- Add a fraud alert to your credit file as an added layer while you decide whether a freeze makes sense for your situation.
- Pull your free credit reports at annualcreditreport.com and look for accounts or inquiries you don’t recognize.
- Watch your existing bank, credit card, and insurance statements closely for unfamiliar activity over the next 12 to 24 months, as Landmark itself recommends.
- Consider signing up for a service like Aura or LifeLock, which can alert you if your information turns up somewhere it shouldn’t, giving you an early warning beyond what a one-time credit check would catch.
- If you spot signs of misuse, file a report with local police and with the FTC at identitytheft.gov, and keep copies for your records.
Questions about this notice can be directed to IDX at 1-866-273-9228 or through https://response.idx.us/landmark, both available Monday through Friday from 9:00 a.m. to 9:00 p.m. Eastern time.