Massive Data Breach at NTT DATA Americas Exposes Standard Insurance Customers’ Personal Details

In a recent incident, the personal details of Standard Insurance customers were exposed in a data breach. The breach occurred on servers belonging to PBI Research Services, a company processing data for Standard Insurance, and was being hosted by NTT DATA Americas. This breach has impacted over 300,000 individuals, highlighting the urgent need for stronger cybersecurity measures.

Impact and exposure

The attacker gained unauthorized access to Standard Insurance data through the MOVEit Transfer service used by PBI Research Services. NTT DATA Americas, the subsidiary of the Japanese multinational IT company NTT DATA, has informed affected individuals about the breach. According to information disclosed to the Maine Attorney General, approximately 308,072 people had their personal details compromised in this attack.

Risks of Social Security Number (SSN) exposure

The compromised personal details include names and Social Security numbers (SSNs). The exposure of SSNs poses significant risks as the stolen data can be used by impersonators for identity theft. Combined with names and driver’s license numbers, stolen SSNs provide the necessary ammunition for criminals to commit various forms of fraud, including financial and medical identity theft. This breach underscores the critical importance of protecting such sensitive information.

Role of PBI Research Services

PBI Research Services, a US-based population management solutions provider, was exposed to this attack due to the utilization of the MOVEit Transfer service. This platform served as the entry point for the malicious actors to gain unauthorized access to the data processed for Standard Insurance. The incident emphasizes the need for organizations to conduct thorough risk assessments and ensure the security of third-party services they rely on.

NTT DATA Americas: A Major IT Player

NTT DATA Americas, a subsidiary of the Japanese multinational IT company NTT DATA, plays a crucial role in the incident. With over 139,000 employees and revenues exceeding $30 billion, NTT DATA is a major player in the global technology industry. However, this breach raises concerns about the company’s security protocols and highlights the importance of implementing robust cybersecurity measures.

Scope of MOVEit Transfer attacks

The MOVEit Transfer attacks have caused widespread damage. Over 980 organizations and nearly 60 million individuals have been confirmed to be impacted by these attacks. The ransomware gang Cl0p has claimed responsibility for these breaches, targeting various sectors and industries. This extensive scale of the attacks reveals the urgent need for enhanced cybersecurity practices and vigilance in the face of evolving threats.

Other affected organizations

Standard Insurance is not the only organization affected by the MOVEit Transfer attacks. Numerous well-known companies, including TD Ameritrade and American Airlines, have had their clients’ personal data exposed in this breach. The significant list of targeted entities also includes TJX, TomTom, Pioneer Electronics, and AMC Theatres. These incidents highlight the importance of organizations, irrespective of their size or industry, prioritizing cybersecurity as a foundational element of their operations.

The massive data breach at NTT DATA Americas, impacting Standard Insurance customers, serves as a wake-up call for organizations around the world. The exposure of personal details, including Social Security numbers, underscores the severe risks posed by such incidents. It is crucial for businesses to invest in robust cybersecurity measures, conduct regular risk assessments, and ensure the security of their third-party service providers. This incident highlights the need for heightened vigilance and comprehensive security protocols to protect sensitive personal information from falling into the wrong hands.

Explore more

AI Drives the Shift to Specialized Data Center Design

The rigid architectural paradigms that once defined data center engineering are currently being dismantled by the insatiable computational demands of modern artificial intelligence. For several decades, the industry adhered to a singular gold standard of universal redundancy, where every piece of hardware was supported by massive backup systems regardless of its actual function. This era of over-engineering is rapidly coming

Global Industrial Motherboard Market to Grow Through 2035

The digital nervous system of the modern smart factory is no longer found in centralized data centers but resides within the ruggedized circuitry of industrial motherboards that power everything from robotic arms to precision medical scanners. This fundamental shift marks a transition for these specialized circuit boards, elevating them from niche hardware components to essential pillars of the global industrial

How Did Microsoft Migrate 70TB to SAP S/4HANA Private Cloud?

Managing the financial heartbeat of a global tech giant involves processing millions of complex transactions across diverse product lines ranging from gaming to cloud services. When Microsoft decided to modernize its core financial infrastructure, it faced the monumental task of migrating a 70-terabyte SAP ERP Central Component system to the SAP S/4HANA Private Cloud. This specific environment, known as SAP

Is Your VPN Gateway an Open Door for Qilin Ransomware?

The sudden realization that a primary security perimeter has been compromised often sends shockwaves through an entire organization, especially when that perimeter is a trusted VPN gateway. When Palo Alto Networks disclosed the CVE-2026-0257 vulnerability in its GlobalProtect firewalls, the severity was immediately clear through its critical CVSS score of 9.1. This specific flaw allows unauthorized actors to bypass authentication

How Data Contracts Stop Data Pipelines From Breaking

A silent failure in a data warehouse often begins with a seemingly harmless change made by an upstream software engineering team that has no visibility into how their data is consumed. When an application developer decides to rename a field from “user_id” to “customer_uuid” or changes a data type to optimize performance, the ripple effect can be catastrophic for the