[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1zbj2fzu0ajw1":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":12,"affectedCountUnit":20,"hasEnglishDescription":4,"contentLocale":21,"availableLocales":22,"translations":24,"severity":27,"dataClasses":28,"description":35,"seoTitle":36,"seoDescription":37,"logoUrl":38,"isVerified":4,"isSensitive":39,"isSpamList":39,"isMalware":39,"company":40},"6a452308a20f867c8ba8e771","kemper","Kemper 2026 Data Breach","kemper.com","2026-04-15T00:00:00.000Z","2026-05-28T07:22:18.000Z",null,"2026-07-29T20:49:57.201Z","verified breach index and security reporting","https:\u002F\u002Fcybernews.com\u002Fsecurity\u002Fkemper-insurance-data-leak-shinyhunters\u002F",[15,17],"https:\u002F\u002Fwww.kemper.com\u002F",269299,"known","email_identifiers","en",[21,23],"tr",{"en":25,"tr":26},{"slug":7},{"slug":7},"High",[29,30,31,32,33,34],"Email addresses","Names","Partial credit card data","Phone numbers","Physical addresses","Purchases","\u003Cp>\u003Cstrong>The Kemper 2026 data-breach record\u003C\u002Fstrong> covers the event in which ShinyHunters named the insurer on a data-publication site on April 15, 2026. Kemper confirmed that it was investigating a cybersecurity incident with specialist support and had notified law enforcement; it said operations were not disrupted. A verified external breach index reports 269,299 unique email addresses in the published corpus. Production has no local import or person-level data.\u003C\u002Fp>\n\n\u003Ch2>How does the publication claim differ from the verified measure?\u003C\u002Fh2>\n\u003Cp>The threat actor claimed to have published more than 29 GB and over 13 million records obtained from Kemper's Salesforce environment. Independent researchers saw folders labelled SharePoint, Azure, Salesforce, and Stripe in a sample, along with internal documents, employee names and emails, and transaction logs. The company statement confirms an incident investigation, but it does not confirm the claimed 13 million rows, data volume, or initial access method.\u003C\u002Fp>\n\n\u003Cp>The 269,299 value measures unique email addresses in the published external corpus. The threat actor's claim of more than 13 million rows is not a people or account count and has not been independently authenticated in full. Repeated log rows and unique emails have different units, so the figures are neither added nor treated as interchangeable. April 15 is the external catalogue and data-publication date; the date of initial system access has not been disclosed.\u003C\u002Fp>\n\n\u003Ch2>Which data fields are in scope?\u003C\u002Fh2>\n\u003Cp>The verified external index lists six structured classes: email addresses, names, phone numbers, physical addresses, purchases, and partial payment-card data. Its narrative describes the partial-card fields as the last four digits, expiry dates, and card brands. It should not be assumed that every field occurred for every email address or belonged to the same person.\u003C\u002Fp>\n\n\u003Cp>The independent researchers also noted that the Stripe sample they could inspect contained no explicit card number or bank-account information. That limited sample finding is not the same measurement as the partial-card class listed across the broader external corpus. Full card numbers, bank accounts, Social Security numbers, passwords, and policy numbers are not among the verified structured classes.\u003C\u002Fp>\n\n\u003Ch2>Attribution and local-coverage boundary\u003C\u002Fh2>\n\u003Cp>The sources associate the event with a wider social-engineering campaign against hundreds of Salesforce customers; Kemper's public statement does not confirm the initial entry method in its own environment. The active company domain verifies the insurance-service identity, not the technical attribution by itself.\u003C\u002Fp>\n\n\u003Cp>Production has no Kemper import job, and every local person-data collection contains zero links. The 269,299 unique emails are therefore not local search coverage. People who received an incident-related notice can verify unexpected payment or policy messages through an existing policy account or a separately obtained official channel; the presence of some accurate contact details in a message is not proof that it is trustworthy.\u003C\u002Fp>","Kemper 2026 Data Breach (269.3 Thousand Email Identifiers)","The Kemper 2026 event contains 269,299 verified unique emails. The claim of more than 13 million rows is a separate, unverified measure.","\u002Fuploads\u002Flogo\u002Fkemper_com.webp",false,{"name":41,"sector":42,"country":43,"website":9,"websiteArchiveUrl":44,"websiteStatus":45,"websiteCheckedAt":46},"Kemper Corporation","Insurance","United States","","active","2026-07-29T20:43:00.000Z"]