LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Tower Insurance NEW Listed by Coinbase Cartel Ransomware Group

HIGH severityUnverified claimHow we verify

Tower Insurance NEW Listed by Coinbase Cartel Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 22, 2026

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Tower Insurance NEW Listed by Coinbase Cartel Ransomware Group

Reported August 22, 2026.

HIGH
Severity
August 22, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Tower Insurance NEW has been listed by the Coinbase Cartel ransomware group, with the disclosure reported on 22 August 2026. An undisclosed number of individuals may have had personal data exposed; customers are advised to check their accounts and monitor for suspicious activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On August 22, 2026, the ransomware and extortion group known as Coinbase Cartel listed Tower Insurance NEW on its leak site. The listing presents the organisation as an insurance-sector target and includes a figure of $283.7 million in the group’s own summary line. Public detail beyond that listing is limited. Tower Insurance NEW has not publicly confirmed the claim as of writing, and independent verification from regulators or established breach indexes is not part of the available record.

Listings of this kind are accusations used for pressure. They do not by themselves prove that systems were compromised, that files left the organisation, or that any particular customer or employee record is in circulation. What follows separates what the group claims from what remains undisclosed, and sets out conditional steps people can take if they later learn they were affected.

What is being claimed

Coinbase Cartel has listed Tower Insurance NEW on its leak site, with the report dated August 22, 2026. According to the listing’s summary framing, the organisation is described as insurance-related and associated with a $283.7 million figure. The group has not, in the facts available here, published a confirmed count of people affected, a technical description of how access was supposedly obtained, or an inventory of file types.

The number of people affected is unknown. Data types named as exposed are not disclosed. Timing of any alleged intrusion, duration of access, and whether a ransom demand was made or paid are likewise undisclosed in the material provided. The listing should be read as a claim by the group, not as a completed forensic finding. Until the company or a competent authority confirms otherwise, the public record on this specific incident remains the leak-site entry and the limited summary attached to it.

Inside Coinbase Cartel

Coinbase Cartel is known in public reporting as a ransomware and data-extortion actor that uses leak sites to name organisations and threaten publication of material it says it holds. Like other groups in this category, it typically seeks leverage by combining alleged access with timed disclosure pressure, rather than relying only on encryption. Public coverage of such crews often describes double-extortion patterns: claims of theft paired with threats to release data if payment is not made.

Well-documented behaviour across this class of actors includes posting victim names, sector tags, and sometimes sample files or screenshots as proof-of-claim marketing. Those posts are not independent audits. For this case, the only incident-specific assertion tied to the facts is that Coinbase Cartel has listed Tower Insurance NEW and framed it with an insurance label and a $283.7 million summary figure. No further quotes, file lists, or method claims about this victim are established in the given record, and none should be invented.

Who is Tower Insurance NEW?

Tower Insurance NEW is identified in the listing as an insurance organisation. Firms in the insurance sector generally underwrite policies, handle claims, and maintain ongoing relationships with policyholders, beneficiaries, brokers, and employees. That work routinely involves identity details, contact information, policy and coverage records, claims documentation, payment or billing data, and sometimes health-, property-, or liability-related information depending on the lines of business offered.

A leak-site listing aimed at an insurer matters because of the sensitivity of the data such organisations typically hold and because customers often cannot easily change insurers overnight without coverage gaps. Consequence here is about potential impact if the group’s claims were ever substantiated—not about any proven failure at Tower Insurance NEW. The listing alone does not establish that customer or employee information left the company.

What was likely exposed

The facts state that data types named as exposed are not disclosed. It is therefore not possible to say what, if anything, was taken. Coinbase Cartel’s listing does not supply a verified inventory, and treating an extortion page as a catalogue would overstate what is known.

If files were taken from an insurer, organisations in this sector typically hold some combination of the following categories—spoken of here only as sector norms, not as confirmed contents of any alleged haul:

Exact contents in this case remain unconfirmed. People affected, if any, are unknown. Readers should not assume their records are included solely because a group posted a name and a sector tag.

Why it matters

For individuals, the practical risk if insurance-related personal data were ever misused includes targeted phishing that references policies or claims, identity fraud that abuses identity attributes, and social-engineering attempts against banks or other providers using details that sound legitimate. Those risks are conditional: they apply if personal information was actually obtained and if it is usable by criminals. A leak-site listing does not automatically mean any of that has occurred.

For the organisation, a public extortion listing can create operational, legal, and reputational pressure regardless of eventual confirmation. Customers and partners may seek clarity; regulators may ask questions when a named firm appears on a criminal site. None of that settles whether a breach happened. What a leak-site listing establishes is that a group chose to name the company. What it does not establish is scope, method, negligence, or confirmed data loss.

The $283.7 million figure appears in the group’s summary line. Without independent confirmation, it should not be read as a verified measure of damage, ransom, or revenue impact. Scale of human impact remains unknown.

If your data was involved

If you are a customer, claimant, or employee of Tower Insurance NEW and you later receive notice that your information was involved—or if you see concrete signs of misuse—treat the situation as conditional and act in layers. Preserve any official notice. Be cautious of unexpected messages that urge urgent payment, password entry, or transfer of funds while claiming to relate to a claim or policy. Prefer contact channels you already trust rather than links or numbers supplied in unsolicited mail.

Practical first steps if involvement is confirmed or strongly suspected include: monitor policy, bank, and credit accounts for unfamiliar activity; consider fraud alerts or credit monitoring where available in your jurisdiction; update passwords on important accounts and enable multi-factor authentication where offered; and document suspicious contacts. Do not assume your data is “out” solely from the existence of the listing.

You can also run a free exposure scan of your email to check whether your information has surfaced in known breach data. That kind of check will not prove or disprove this specific listing, but it can show whether your address already appears in other documented corpora and help you prioritise further hardening of accounts that reuse that address.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyTower Insurance NEW security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Tower Insurance NEW’s full breach history →

More recent breaches

PT Perusahaan Jamu Air Mancur NEW Listed by Coinbase Cartel Ransomware GroupAugust 22, 2026PT. Bank Perekonomian Rakyat Bintan NEW Listed by Coinbase Cartel Ransomware GroupAugust 22, 2026LifeBank Microfinance Foundation NEW Listed by Coinbase Cartel Ransomware GroupAugust 22, 2026Kessler Creative NEW Listed by Coinbase Cartel Ransomware GroupAugust 22, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Tower Insurance NEW Listed by Coinbase Cartel Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by coinbase-cartel — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram