SYS::ONLINE
Wasteland.
Briefs2208
Issues24
SinceFeb 2026
LIVE
█ Ransomware TOWER-INSURANCE-CO 2026-08-24

Tower Insurance: CoinbaseCartel Ransomware Extortion Claim

"On 22 August 2026, the ransomware and extortion crew tracked as CoinbaseCartel added Tower Insurance (tower.co.nz) to its leak site, threatening to publish stolen data unless the New Zealand insurer opens negotiations…"

On 22 August 2026, the ransomware and extortion crew tracked as CoinbaseCartel added Tower Insurance (tower.co.nz) to its leak site, threatening to publish stolen data unless the New Zealand insurer opens negotiations. Ransomware.live logged the victim entry at 14:00 UTC on 22 August and lists the estimated attack date as the same day. Tower is an NZX-listed general insurer founded in 1869, roughly 600 to 700 staff, writing home, contents, motor, travel and commercial cover across New Zealand and the Pacific. Every source available on this incident is third-tier monitoring or aggregator reporting. There is no Tower statement, no NZX disclosure, no NCSC NZ advisory and no vendor incident report in the source set, so at the time of writing this remains a threat-actor claim rather than a confirmed intrusion.

What Happened

The sequence is consistent across the monitoring sources. CoinbaseCartel published a victim entry for Tower Insurance on 22 August 2026 carrying a short extortion ultimatum. DeXpose quotes the posting directly: "The full leak will be published soon, unless a company representative contacts us via the channels provided." That is a pre-leak pressure post, the phase before any sample dump, and it implies the group either has data it has not yet published or wants Tower to believe it does.

Where the sources diverge is on impact. UndercodeNews published two pieces within roughly two hours of each other on 22 August that do not agree with each other. The first, citing ThreatMon's victim-list monitoring, states plainly that the report "represents threat-actor activity and victim-list claims, rather than independently confirmed evidence that either organization suffered a successful ransomware intrusion," and notes that no initial access method, ransom demand, encryption activity or data volume was disclosed. That same piece pairs Tower with a separate ShinyHunters claim against BOK Financial posted minutes apart. The second UndercodeNews article, attributing to reporting from Cybersecurity News Everyday, goes considerably further and describes the incident as having "affected the company's digital policy and claims operations."

Accounts differ, and the more cautious version is better supported. No source in this set carries a Tower confirmation of service disruption, and the claimed policy and claims impact traces to a single downstream aggregator citing another aggregator. Treat operational disruption as unverified until Tower or a regulator says otherwise.

What Was Taken

Nothing is confirmed. No data volume, record count, file listing or victim category has been published by CoinbaseCartel in the material available, and no sample dump appears in any source. Anyone quoting a record count for this incident right now is inventing it.

What the sources do provide is exposure context rather than breach evidence. Ransomware.live's HudsonRock integration reports 0 compromised employees, 486 compromised users, 4 third-party employee credentials and an external attack surface of 10 associated with the Tower domain. Those are infostealer-log and attack-surface figures collected independently of this claim. They indicate credential exposure in the ecosystem around Tower, not proof that any of those credentials were the access vector.

The plausible data profile, if the claim is real, follows from what the business holds: policy records, claims files with supporting documentation, identity data, bank and payment details, and in a general insurer's case property addresses and loss assessments. Tower's Pacific Islands operations broaden the jurisdictional footprint beyond New Zealand's Privacy Act.

Two comparison points are useful for calibrating expectations. CoinbaseCartel's June 2026 claim against Cambridge Mobile Telematics involved, per a US plaintiffs' firm investigating it, driving behaviour telemetry, GPS location history and insurance-related profile data. The group's Colliers Real Estate victim record indexed by Dark Eye includes proof-of-breach screenshots showing a file tree, a finance spreadsheet, a passport scan and a signed contract. That is the group's normal evidence pattern, and its absence in the Tower posting is itself a data point.

Why It Matters

Tower would be a significant New Zealand target. A listed insurer with 600 to 700 employees, a digital-first claims and policy platform and operations spanning 17 countries carries continuous disclosure obligations to the NZX and privacy breach notification duties to the Office of the Privacy Commissioner. The silence in the source record is therefore notable in both directions: it may mean investigation is ongoing and premature disclosure was avoided, or it may mean the claim does not correspond to a material incident.

The insurance sector angle is real. Insurers concentrate exactly the material extortion crews monetise, and CoinbaseCartel has now been linked to at least two insurance-adjacent victims in three months, Cambridge Mobile Telematics in June and Tower in August, alongside real estate services firm Colliers. This is a group working the financial and professional services seam rather than opportunistically hitting whatever it lands on.

The downstream consequences of unconfirmed claims also matter. The Cambridge Mobile Telematics case shows the trajectory: within six weeks of the leak site posting, a US class action firm was publicly investigating and framing the absence of victim notification as a potential legal violation. Whatever the technical truth of a leak site entry, the legal and reputational clock starts when the post goes up.

There is a defensive lesson in the disclosure lag as well. Dark Eye's Colliers record shows a 51 day gap between the leak-site publication date of 20 July 2026 and the disclosure date recorded as 30 May 2026, an inverted timeline reflecting that the compromise was known and notified well before the operator published. Leak-site appearance and actual breach timing are only loosely coupled, in either direction.

The Attack Technique

Unknown. No source describes initial access, lateral movement, encryption, exfiltration tooling or ransom amount, and UndercodeNews explicitly flags that absence. CoinbaseCartel's public behaviour across its Tower, Cambridge Mobile Telematics and Colliers entries is consistent with a data-theft extortion model, where the leverage is publication rather than encryption, but the sources do not establish that encryption did or did not occur here.

The only technically suggestive signal available is the HudsonRock infostealer data: 486 compromised users and 4 third-party employee credentials tied to the Tower domain. Stolen session cookies and credentials from infostealer logs are among the most common entry routes for this class of actor, and DeXpose's own guidance leans on that assumption. It remains an inference, not a finding.

Publicly visible infrastructure from the Ransomware.live DNS record set gives defenders a rough sense of the environment: Proofpoint handles inbound mail, and verification records point to Microsoft 365, Google Workspace, Firebase, Dynamics 365 Marketing, Docebo, Canva and Miro. That is a broad SaaS estate, which is a broad identity attack surface. Tower's security function is led by Head of Information Security Darren Beattie, in the role since March 2023 after several years running networks, access and security operations internally.

What Organizations Should Do

Sources: CoinbaseCartel Strikes Tower Insurance in New Zealand - DeXpose | Ransomware.live - Victim: Tower Insurance | Tower Insurance Hit by Coinbasecartel Ransomware, New Zealand Insur... | Two New Ransomware Claims Rock the Insurance and Banking Sectors as... | PRIVACY ALERT: Cambridge Mobile Telematics Under Investigation for... | Cognizant notifies individuals of data breach; offers $1 mn identit... | Colliers Real Estate — COINBASECARTEL Ransomware Attack Dark Eye | Darren Beattie