Specialty insurance files list the assets, locations, contractors, and counterparties a client has already decided to protect. Ransomware.live listed NationsBuilders Insurance Services as claimed by Aurora on 22 June 2026. The listing remains a claim posting; no confirmation from the company has been issued.
The files in question contain policy administration records, claims documentation, contractor schedules, risk assessments, coverage limits, payment instructions, and correspondence tied to active losses. For family offices and principals, those records map exactly what an adversary needs to impersonate a legitimate party.
How the data supports impersonation
An attacker with policy numbers, claim references, renewal dates, named contractors, or vehicle and property schedules can reference real details in an email or call. That detail is enough to request a change in payment instructions, ask for updated loss documents, introduce a new vendor portal, or trigger a refund. The request looks routine because the facts are accurate.
No full file is required. Partial but current data from one carrier is sufficient to reach the right contact at the right moment.
Immediate checks required
Review every client, trust, or adviser that holds or has held a policy with NationsBuilders or uses the same brokers and claims administrators. Identify which staff can approve payment redirects, release documents, or update vendor details based only on email. Map which external parties already appear in the exposed records.
Any workflow that treats an insurance reference as proof of identity needs to be cut off.
Secvred control layer
Secvred would have mapped every active NationsBuilders policy held by its clients, including the named brokers, claims handlers, and finance contacts attached to those policies. It would have removed policy numbers, claim dates, and contractor schedules from any inbox or shared drive accessible by standard email accounts. Payment changes and document releases tied to claims would have been locked to a pre-verified phone line or portal token that cannot be reset through email. Stale user accounts on the carrier portal would have been deleted. Staff would have been instructed that any request citing a NationsBuilders policy number still requires an out-of-band callback to a known contact before any action is taken.
How the exposure is used
Insurance records do not need to be stolen in bulk to create leverage. Once the details surface, they supply the language an attacker uses to move money or extract further documents. The controls that stop the move are the same ones that keep policy facts from functioning as identity.