MagMutual Data Breach Exposes Clinical and Financial Information

Published
July 22, 2026
Updated
July 22, 2026
MagMutual Data Breach Exposes Clinical and Financial Information
MagMutual Insurance Company
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

MagMutual Insurance Co., a physician-owned medical malpractice insurance company based in Atlanta, disclosed a data breach involving unauthorized access to its computer systems.

MagMutual, which was founded in 1982 and provides coverage to more than 50,000 healthcare providers and organizations across the United States, has not disclosed the total number of individuals affected.

On or around April 28, 2026, MagMutual became aware of suspicious activity within its computer environmen. The company began working to investigate and address the issue.

On May 3, 2026, MagMutual was alerted to ongoing unauthorized activity within its systems. The company continued its investigation with the assistance of third-party cybersecurity specialists to determine the full nature and scope of the incident.

The investigation found that an unauthorized party had access to MagMutual's computer environment between April 28, 2026, and May 4, 2026. During that period, certain files and folders within the network may have been improperly accessed or taken without authorization.

Roughly seven weeks later, on June 23, 2026, a threat actor known as Leaknet posted a claim on a dark web forum. The threat actor stated it had acquired data belonging to MagMutual and intended to publish the data within one to two days.

The types of information potentially exposed in the breach include names, clinical information, demographic information and financial information.

The company posted a notice of the privacy incident on its website.

MagMutual Insurance's response to the breach

MagMutual has established a dedicated phone line for individuals who believe they may have been affected by the breach. The number is 888-289-7022, and it is available from 9 a.m. to 9 p.m. ET, Monday through Friday.

Individuals can also contact the company by mail at PO Box 52979, Atlanta, GA 30355.

The company encouraged potentially affected individuals to remain vigilant against identity theft and fraud by reviewing account statements and monitoring free credit reports for suspicious activity over the next 12 to 24 months.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image