Overview
- Insight Partners says a threat actor used a sophisticated social engineering attack to access its servers on or around October 25, 2024.
- After exfiltrating data, the attackers began encrypting servers at about 10:00 a.m. EST on January 16, 2025, consistent with ransomware activity.
- The company reported to Maine that 12,657 individuals were affected, including current and former employees as well as limited partners.
- Stolen information includes fund, management company and portfolio company data, plus banking, tax, and personal details tied to employees and investors.
- Formal notification letters are being mailed with complimentary credit or identity monitoring, and the firm has not disclosed any extortion demands, ransom payments, or the responsible group.