ConfirmedData breach

Kemper: a data breach

In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign . The attackers allegedly accessed Kemper's Salesforce environment via social engineering as part of a broader campaign targeting hundreds of organisations using the same method. The group later published tens of gigabytes of data they claimed included internal directory data, Salesforce records and Stripe payment logs. Among the 269k unique email addresses were names, phone numbers, physical addresses and partial payment card data including the last 4 digits, expiry dates and card brands. Kemper confirmed the incident and stated they had engaged third-party cybersecurity experts and notified law enforcement.

The record

Organisation
Kemper
Identity
Kemperidentified by its domain in a verified breach record
Records affected
269,299 records
Data exposed
Email addresses, Names, Partial credit card data, Phone numbers, Physical addresses, Purchases
Sector
Not recorded
Occurred
2026-04-15
Disclosed
2026-05-28
First recorded here
2026-09-09

Sources (1)

One source so far.

  1. Have I Been PwnedFirst reported

    2026-05-28