American Contractors Insurance Group Data Breach

Alleged

Ransomware claim involving American Contractors Insurance Group

Published: Aug 19, 2026 Storm
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
American Contractors Insurance Group
Industry
Finance
Threat Actor
Storm
Date of Incident
Aug 19, 2026

Executive Summary

American Contractors Insurance Group, a provider of specialty insurance for construction contractors in the United States, was listed as a victim by the Storm ransomware group on August 19, 2026. This identification was made through SOCRadar’s Dark Web Monitoring service. The company’s focus on specialty insurance makes it a potentially attractive target for ransomware actors, as such organizations typically possess sensitive data including policyholder personally identifiable information (PII), claims histories, and financial records of contractors. This data often carries regulatory disclosure obligations, which can amplify the leverage for extortion. Storm ransomware has a documented history of targeting financial services and specialty insurance companies, indicating a strategic choice based on the sensitivity and value of the data these entities hold. The Storm ransomware group has been active, with this listing occurring within a period where they are actively claiming victims. The group frequently targets the financial services and insurance sectors, and their primary victim base is located in the United States, aligning with the profile of American Contractors Insurance Group. This targeting pattern suggests that ACIG fits within Storm’s typical operational strategy, where sensitive financial and customer data can be effectively leveraged for ransom demands.

Technical Analysis

SOCRadar’s query of the domain acig[.]com, related to American Contractors Insurance Group, yielded 7 records from stealer logs. These records included 3 credentials identified as customer credentials and 4 of an unclear affiliation. Analysis of the customer records revealed authentication attempts against password-reset portals and FTP endpoints. The password-reset activity suggests potential account takeover attempts targeting users who already possess authenticated access. The presence of FTP access logs is particularly noteworthy, as insurance company FTP servers are commonly used for transferring large files between the insurer, agents, brokers, and reinsurers. Compromise of FTP servers could lead to the exposure of sensitive data belonging not only to American Contractors Insurance Group but also to its distribution partners and clients. The timeframe of the observed credential exposure spans from February 2024 to August 11, 2026, indicating a prolonged period of potential vulnerability, with the most recent record surfacing just eight days prior to the Storm ransomware group’s listing. This extensive exposure window highlights the persistent nature of the threat. Organizations should audit FTP access logs across the identified full window of exposure. It is recommended to force-reset customer accounts where password-reset flows are evident within the stealer sample. Furthermore, a thorough assessment should be conducted to determine if any policyholder or partner data was accessible via the compromised FTP servers.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.