Cyberattack on Almerys Exposes Sensitive Data of Alan's Members
Article Content
- •Almerys suffered a cyberattack exposing sensitive data of Alan's members.
- •Over 15 million unique social security numbers may be compromised.
- •Alan advises members to be cautious of phishing attempts following the breach.
On May 24, 2026, Almerys, a third-party payment provider, reported a cyberattack that compromised sensitive data of members from the health insurer Alan. The breach exposed personal information including full civil status, social security numbers, and contract numbers, affecting potentially over 15 million unique social security numbers. Alan confirmed that no intrusion occurred on its own servers and that financial data, passwords, and health information remained secure. The attacker claimed to have access to family information linked to social security numbers, increasing the risk of identity theft. Alan has advised its members to be vigilant against phishing attempts in the wake of the breach. Almerys had previously suffered a similar attack in January 2024, affecting over 33 million individuals, with investigations still ongoing. The current attack has raised concerns about the effectiveness of security measures at Almerys, particularly the lack of two-factor authentication.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Almerys in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…
Critical RCE Vulnerability in F5 BIG-IP APM Exploited in the Wild A severe heap-based buffer overflow vulnerability, tracked as CVE-2026-94127, has been identified in F5 BIG-IP Access Policy Manager (APM), allowing unauthenticated remote code execution (RCE) on the Traffic Management Microkernel (TMM) data plane. This vulnerability is triggered when both an APM access policy and an…