Recommended Free Tools
Two separate 2024 data breaches at insurance-related service providers may have affected a combined 2,633,881 people, according to revised estimates reported by SecurityWeek in 2025. The figures—1,613,773 for Landmark Admin and 1,020,108 for Young Consulting—are potential-impact estimates, not a confirmed count of unique individuals across both incidents.
Two separate breaches, not one shared incident
Landmark Admin and Young Consulting are separate organizations, and the reported incidents occurred at different times in 2024. Both provided services connected to insurance or health plans, so their incidents raised concerns about sensitive information held by vendors. SecurityWeek reported the revised counts from Maine filings in 2025; the filings themselves were not independently accessible for review.
| Organization | Incident timing | Revised potential-impact estimate | Earlier estimate or notice |
|---|---|---|---|
| Landmark Admin | Initial unauthorized access identified May 13, 2024; another access event occurred June 17, 2024 | 1,613,773 people, per SecurityWeek’s 2025 report of a revised Maine filing | About 800,000 people in the October 2024 notice, as reported by Comparitech |
| Young Consulting | Network access reported from April 10 through April 13, 2024 | 1,020,108 people, per SecurityWeek’s 2025 report of a revised Maine filing | 954,177 in the initial estimate, later revised after a data review |
The two revised estimates add up to 2,633,881. Because the reports do not establish whether any person appears in both counts, that total should not be read as a verified count of distinct people.
What happened at Landmark Admin
Landmark Admin, a third-party insurance administrator, reportedly identified unauthorized access on May 13, 2024. A second access event occurred on June 17 while the company was investigating. Reporting on the later Maine filing said stolen VPN credentials were used.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
Landmark said investigators found that data had been exfiltrated, but could not identify the specific files or folders taken during the re-entry. It also said it had no evidence that personal information was exfiltrated. These statements describe different uncertainties: data left the environment, but the investigation did not establish which records were involved or confirm that personal information was among them. SecurityWeek reproduced Landmark’s statement using the spelling “Lankmark” in the quoted text.
Reported categories of information potentially involved included names, addresses, dates of birth, Social Security numbers, tax identification numbers, driver’s-license numbers, government ID and passport numbers, financial account information, medical and health-insurance information, and insurance policy details. The reported estimate increased from roughly 800,000 people in the October 2024 notice to 1,613,773 in the later Maine filing summarized by SecurityWeek in 2025.
What happened at Young Consulting
Young Consulting’s separate incident occurred in April 2024. Earlier reporting said attackers accessed its network from April 10 through April 13 and copied files that included or could include names, dates of birth, Social Security numbers, insurance policy or claim information, prescriptions, and provider names.
The company later revised its estimated potential impact from 954,177 to 1,020,108 people after reviewing data. SecurityWeek reported that Young Consulting determined in January 2025 that more people were affected than it had first estimated. The company said information potentially subject to unauthorized access included names, Social Security numbers, tax ID numbers, and health information.
Free tools Windows power users keep installed
One-click scans. No signup required.
SecurityWeek reported that the BlackSuit group claimed responsibility and made allegedly stolen data available for download. That is an attribution claim, not independent confirmation of who carried out the attack.
Why a vendor breach can concern health-plan members
A company that administers insurance or provides risk-management services may handle personal information for another organization. That can expose people to a vendor incident even if their insurer’s own network is not shown to have been breached.
Blue Shield of California’s August 26, 2024 notice said Young Consulting, a third-party risk-management vendor, notified it of a security event potentially affecting health-plan members’ information. Blue Shield said it had no evidence that its own health-plan systems were affected. That statement does not establish that members’ information was unaffected; the notice described a potential impact involving the vendor.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What affected people can do
If you received a notice from Landmark Admin, Young Consulting, or a health plan connected to either company, use the instructions in that notice to determine whether your information may have been involved. The reported data categories vary, so the notice is the best source for your particular circumstances.
Best Value
- Watch accounts tied to the information listed. Review financial, insurance, and health-related statements for unfamiliar activity, and contact the institution through a trusted phone number or website if something looks wrong.
- Protect exposed identifiers. If the notice says your Social Security number may have been involved, consider placing a credit freeze with each of the three nationwide credit bureaus. A freeze is free and restricts access to your credit file for most new-credit applications; it does not stop every kind of identity misuse.
- Use strong, unique credentials. If an account password may have been exposed or reused, change it and enable multifactor authentication where available. Do not follow unexpected links or share account credentials in response to a message about the breach.
- Check any monitoring offer carefully. Comparitech reported that Landmark offered affected people one year of IDX credit monitoring and identity theft protection at the time of its initial report. Current enrollment availability and terms have not been established, so confirm details in an official notice before relying on the offer.
What the reported counts do—and do not—show
The revised figures indicate how many people may have been affected according to the reported filings. They do not prove that every person’s data was accessed, that every listed data type applied to every person, or that all records were removed by attackers. In Landmark’s case, the company reported exfiltration but said it could not identify the specific files or folders taken during the later access. For both incidents, the available reporting describes potential impact, not a verified number of people who experienced identity theft.
Blue Shield’s notice and the company statements summarized by SecurityWeek provide incident context, while the revised counts and filing details here are attributed to SecurityWeek’s 2025 reporting. Its report of the Maine filings could not be independently checked against the filings themselves.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




