All Breaches
April 28, 2026 Verified Sensitive Record Insurance

MagMutual 2026 Data Breach

The MagMutual 2026 data breach resulted from unauthorized access to the computer environment of a medical-professional liability insurer from April 28 through May 4, 2026. MagMutual identified suspicious activity around April 28 and began investigation and remediation; it was alerted again on May 3 to ongoing activity.

An investigation with third-party specialists found that certain network files and folders may have been improperly accessed or taken without authorization. The organization described the possible data scope as names plus clinical, demographic, and financial information. Because no deduplicated nationwide population was published, LeakData keeps pwnCount and totalRecords at zero, and importedRecordCount is zero.

How Was the MagMutual Breach Confirmed?

The primary source is MagMutual's “Notice of Privacy Incident” on its own domain. The organization directly describes initial discovery, the May 3 alert, April 28–May 4 access window, the finding that files and folders may have been taken, four broad information categories, policy review, regulatory notifications, and assistance line.

Claim Depot connects the official notice with the company profile and independently summarizes the event timeline and possible data fields. The secondary source also reports that an actor called Leaknet claimed responsibility on a dark-web forum June 23. Because MagMutual's public text does not name an actor, LeakData does not present that claim as confirmed technical attribution.

What Happened From April 28 Through May 4, 2026?

MagMutual observed suspicious activity in its computer environment around April 28 and began investigating and addressing the event. The company was alerted May 3 to continuing activity in its systems. Third-party specialists joined the response to establish the nature and scope, ultimately finding that an unauthorized party had access to the environment from April 28 through May 4.

The investigation found that certain network files and folders may have been improperly accessed or taken without authorization during that period. The public notice does not explain the initial entry vector, malware, how credentials may have been obtained, a ransom demand, or publication of files. Qualified language does not prove every file was copied, but it does not remove the risk of data acquisition.

What Demographic Information May Have Been Affected?

MagMutual said a combination of names and demographic information may have been affected. “Demographic” is a broad category; the official page does not separately confirm dates of birth, addresses, Social Security numbers, driver's licenses, passports, telephone numbers, or email addresses. LeakData records only names and the organization's demographic-information category instead of assuming those details.

A name combined with clinical or financial context may enable convincing social engineering that impersonates MagMutual, a healthcare organization, or an insurer. Recipients should not open links or provide account or identity details in unexpected messages and should verify a caller through an independently obtained official number. It should not be assumed that every person had the same data combination.

What Is the Scope of Clinical Information?

The official notice lists clinical information among potentially affected categories and says the page is provided under HIPAA and HITECH substitute-notice requirements. This supports the possible presence of health-related protected information. MagMutual's role in medical-professional liability insurance suggests files could relate to healthcare professionals, organizations, claims, or associated individuals.

The source does not separately confirm diagnoses, treatment, prescriptions, medical-record numbers, laboratory results, provider names, patient names, service dates, or insurance-policy numbers. LeakData keeps clinical information at the breadth disclosed and does not turn possible business context into confirmed fields. Relevant individuals should review health and insurance records for unfamiliar claims or contact changes.

What Are the Risks From Financial Information?

MagMutual also listed financial information as a potentially affected category. The public text does not separately identify bank-account numbers, routing numbers, payment cards, CVVs, PINs, invoices, premiums, payment history, or tax information. LeakData therefore uses only the broad financial-information class and does not treat examples in general credit-protection guidance as incident data.

Notice recipients should review account statements and free credit reports for suspicious activity or errors. MagMutual recommends vigilance for 12 to 24 months. Unfamiliar transactions or account changes should be reported directly to the relevant financial institution. Passwords, card information, or one-time codes should not be given in payment requests claiming to come from MagMutual; reconnect through an official channel.

How Many People Were Affected and How Did MagMutual Respond?

MagMutual's public page does not disclose a nationwide affected-person count. The company's corporate scale of serving more than 50,000 healthcare providers and organizations is not a victim count and cannot be used as pwnCount. LeakData does not create an unverified estimate; pwnCount and totalRecords are zero, and importedRecordCount is zero because no individual rows were imported.

The company opened an expert-assisted investigation, reviewed policies, procedures, and processes, and said it would notify applicable regulators and affected individuals where necessary. Potentially affected people may call 888-289-7022 weekdays from 9 a.m. to 9 p.m. ET. The source does not publish an affirmative finding that no misuse occurred. LeakData does not host incident files or personal records.

0
Affected Accounts
6
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

6
Personal information
Protected health information
Names
Clinical information
Demographic information
Financial information

Additional Information

Added DateJuly 27, 2026
Breach DateApril 28, 2026
Domainmagmutual.com
SourceOfficial MagMutual notice confirming unauthorized computer-environment access and possible access to or taking of files containing names and clinical, demographic, and financial information
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information