Summary
- Environment: GoAnywhere MFT
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
Potential access to or copying of health-plan member and provider information held by Insightin for clients. [1][2][3]
Documented data types include:
- Gender information — Gender information is listed in the California supplemental sample population. [2][3][4]
- Clinical information — Includes healthcare-provider information and medical information reported for some downstream populations. [2][3][4]
- Names [2][3][4]
- Health insurance information — May include insurance information, member IDs, health-plan information, contract numbers, or Medicare Beneficiary Identifiers depending on the individual and client population. [2][3][4]
- Contact information — Texas report BR-0004895 lists addresses among its reported information types. [2][3][4]
- Dates of birth [2][3][4]
- Account credentials — Washington’s directory flags email-address credentials or security-question answers for the three named February 20 downstream plan rows; this is not generalized to every affected individual. [2][3][4]
A cited record reports 11,740 individuals (Washington residents in the Centene Corporation notification row; downstream and non-additive to national regulator totals; as of 2026-03-05). [1]
A cited record reports 843 individuals (Washington residents in the Wellcare Health Insurance Company of Washington notification row; downstream and non-additive; as of 2026-02-20). [1][2][3]
A cited record reports 1,777,141 individuals (Total individuals affected according to Texas report BR-0004895; regulator-reported and retained separately from the HHS OCR population; as of 2026-03-10). [1][2][3]
A cited record reports 2,485 individuals (Washington residents in the Wellcare of Washington notification row; downstream and non-additive; as of 2026-02-20). [1][2][3]
A cited record reports 143,346 individuals (Texas residents according to report BR-0004895; not a national total; as of 2026-03-10). [1][2][3]
A cited record reports 29 individuals (Washington residents in the Coordinated Care of Washington notification row; downstream and non-additive; as of 2026-02-20). [1][2][3]
A cited record reports 1,641 individuals (Approximate Rhode Island resident count in the March 4 sample notice; jurisdiction-scoped and non-additive; as of 2026-03-04). [1][2][3]
A cited record reports 1,949,534 individuals (Individuals in the HHS OCR incident report; regulator-reported, not independently verified, and not reconciled with Texas’s different total; as of 2026-08-08). [1][2][3]
Insightin said an unauthorized party used a previously unknown design flaw in third-party GoAnywhere software to access or copy files on a limited number of Insightin servers; the reviewed sources assign no CVE. [3]
Insightin said it had seen no evidence of identity theft or fraud connected with the incident at the time of its public notice and supplemental sample. [2]
The initial and supplemental California sample populations state that Social Security numbers and financial information were not in the affected files; this negative statement is scoped to those notices and is not generalized beyond them. [2]
Insightin’s supplemental notice says it provided incident information to clients between December 4 and December 18, 2025 and worked with them to identify potentially affected people. [2]
Timeline
Discovery
Insightin’s initial California notice says it identified unusual server activity on this date.
[3]Discovery
Discovery date recorded in Texas report BR-0004895; it conflicts with Insightin’s September 23 notice statement and is retained without reconciliation.
[7]Public disclosure
Publication date recorded in the metadata of Insightin’s public Notice of Data Event page.
[4]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The incident involved GoAnywhere MFT. [3]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
Insightin said the event did not affect its ability to serve customers. Insightin said it engaged forensic specialists, stopped further access, secured its environment, reviewed security policies, added safeguards, and reported the incident to law enforcement and regulators. The California sample notices offered twelve months of Cyberscout single-bureau credit monitoring, credit-report and credit-score services, and proactive fraud assistance. The evidence ledger retains 1 disputed claim with the original citations rather than silently resolving the conflict. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2][3][4]
