TL;DR: The Everest ransomware group published 108 GB of data it claims to have stolen from Liberty Mutual Insurance on May 4, 2026, after the insurer failed to respond to ransom demands. The dump contains 52,429 files across 14,979 folders, including policyholder names, addresses, policy numbers, and financial details. Liberty Mutual calls it a "third-party vendor" incident. The same Everest group is simultaneously threatening Fiserv, the payment processor behind thousands of US banks. If you have a Liberty Mutual policy, your personal information may already be circulating on hacker forums.
The Data Is Already Out There
This is not a ransom threat. The deadline already passed. The data is published.
On April 30, 2026, the Everest ransomware group stole 108 gigabytes of data from systems connected to Liberty Mutual Insurance. On May 4, after Liberty Mutual reportedly failed to respond to demands, Everest dumped the entire trove on its leak site and across multiple hacker forums [1][2].
The leaked archive contains 52,429 files organized into 14,979 folders. Researchers who reviewed sample files found individual policy documents, customer-facing records, generated insurance forms, and corporate client files [2]. The data reportedly includes:
- Policyholder names and home addresses
- Policy numbers and coverage details
- Financial information tied to policies
- Insurance claim records
- Corporate client documentation
File formats in the dump include .doc, .pdf, .txt, .json, .afp, .vpf, and .tgz archives. The entire trove was allegedly created on January 26, 2026, suggesting the attackers had access for months before stealing the data in April [2].
Liberty Mutual Says It Was Not Their Fault
Liberty Mutual's response: this is a vendor problem, not ours.
The company told reporters it is investigating "a possible incident at a third-party vendor" and emphasized that "our current review does not indicate a compromise of Liberty Mutual systems or networks" [1].
If that sounds familiar, it should. This is the same playbook every major company runs when a vendor gets popped. Vimeo said it about Anodot. ADT said it about their contractor. Canvas said it about their API vendor. The data still ends up on the dark web either way.
For policyholders, it does not matter whether Everest broke into Liberty Mutual directly or through a vendor. Your name, your address, and your policy details are still exposed.
Who Is Liberty Mutual
Liberty Mutual is not a small insurer. This is the ninth-largest property and casualty insurer in the world. A Fortune 100 company pulling in $50.5 billion in net revenue in 2025, with over 40,000 employees across 27 countries [3].
They insure homes, cars, businesses, and workers' compensation across the United States and internationally. Millions of American households have a Liberty Mutual policy. If you got a quote from them in the last year, your data could be in this dump.
Everest Is on a Financial Sector Tear
Liberty Mutual is not Everest's only financial-sector target this week. On May 3, 2026, one day before the Liberty Mutual dump, Everest listed Fiserv on its leak site with a similar countdown timer [4]. Fiserv handles payment processing for thousands of US banks and credit unions.
Two major financial institutions targeted by the same group within the same week. Everest's recent hit list reads like a tour of critical infrastructure [4]:
- AT&T: 576,000 applicant records (October 2025)
- Dublin Airport: 1.5 million passenger files (October 2025)
- Svenska kraftnät: 280 GB from Sweden's national power grid
- Fiserv: payment processor for 10,000+ banks (May 3, 2026)
- Liberty Mutual: 108 GB of insurance records (April 30, 2026)
Everest operates a double-extortion model: steal data first, then encrypt systems or threaten publication if the victim does not pay. When victims refuse, the group has been known to sell network access to other threat actors, meaning a second, potentially more destructive attacker could follow [4].
What This Means for Policyholders
If you have or had a Liberty Mutual policy, assume your information is compromised until the company says otherwise. The leaked files reportedly include individual policy documents with personal details.
Watch for:
- Insurance-themed phishing. Emails pretending to be from Liberty Mutual asking you to "verify" your policy or payment details
- Identity theft using your address and financial info. Attackers now have your name tied to specific financial products
- Fraudulent insurance claims filed in your name. Policy numbers combined with personal details make this possible
- Targeted scam calls. If they know you have homeowner's insurance, they know you own property worth insuring
What You Should Do Right Now
- Freeze your credit at all three bureaus (Equifax, Experian, TransUnion). Free. Takes five minutes each.
- Set up fraud alerts on your bank accounts and credit cards
- Monitor your insurance account for unauthorized changes to beneficiaries, coverage, or payment methods
- Be skeptical of any contact claiming to be from Liberty Mutual. Call their number directly, never use links in emails
- Check HaveIBeenPwned.com once this breach is indexed to confirm whether your email appears in the dump
Liberty Mutual has not yet announced credit monitoring for affected customers, and has not disclosed how many people are impacted. Given that this is a Fortune 100 insurer with millions of policyholders, the number could be substantial.
The Vendor Problem Is Getting Worse
Four of the five biggest breaches in the last month followed the same pattern: attackers hit a third-party vendor and used that access to reach the real target's data. Vimeo through Anodot. ADT through a contractor's Okta. Canvas through API keys. Now Liberty Mutual through an unnamed vendor.
Your security is only as strong as the weakest company that touches your data. You never signed up to trust Liberty Mutual's vendor. You never even learned their name. But they had your policy details, and now so does a Russian-speaking ransomware group.
Sources
- BankInfoSecurity: Everest Group Begins Leaking Alleged Liberty Mutual Data (May 2026)
- CyberNews: Hackers claim Liberty Mutual breach exposed thousands of individual insurance records (May 2026)
- Ransomware.live. Victim: Liberty Mutual Insurance (Everest group)
- State of Surveillance. Fiserv Everest Ransomware: The Company Behind Your Bank (May 2026)
Published May 6, 2026. Liberty Mutual has not yet confirmed the number of affected policyholders or announced customer notification. This article will be updated when the company provides additional detail.