SHINDO3

Zurich Insurance

Customersup to1,668people

POSSIBLE LEAKFull name / Email addressUnauthorized access · Investigating

Open in the live monitor ▶
Disclosed
Aug 28, 2026
Detected
Aug 18, 2026
Detection to disclosure
10 days
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
ContactEmail address
Transactions & activityCase management numbers assigned to each claim for loss adjustment

Not leaked

  • Video footage is said not to be included

How many

  • Customers up to 1,668 people

Who is affected

  • Customers

Cause

A vulnerability in Z-Dash, the system used to upload dashcam data, was exploited

Timeline

  1. Unauthorized access on April 1 and April 6, 2026
  2. Intrusion stopped
  3. Vulnerability found
  4. Possible leak identified
  5. System taken offline
  6. First disclosure

Response

  • Service stopped
  • Forensic investigation
  • Notified individuals

Shut down the system and investigating; affected customers will be notified by letter once details are known

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources