← Generation Life

2026 Generation Life — customer data via third-party provider; Qilin listing

2026 Unknown records affected Share on X

Data compromised

Personal information of a limited number of customers confirmed impacted after investigation—specific fields and headcount not publicly quantified; core investment systems and client funds reported unaffected

Technical writeup

Verified breach — April–June 2026. Australian investment and life insurer Generation Life first disclosed April 27, 2026 that an unauthorized party accessed part of its environment through an external service provider, shut access quickly, and found no evidence of impact to core investment systems or unauthorized transactions. By May 17 the company noted Qilin had listed it on a dark-web leak site without publishing samples or data volumes. After a detailed investigation, Generation Life said June 24, 2026 it is notifying a limited number of individuals whose personal information was confirmed impacted, notified APRA, ACSC, OAIC, and NOCS, and that services and client investments remained unaffected. BreachHistory uses recordsAffected 0 because the company has not published an attested count—only that impact is limited.

Root cause

Unauthorized access via external service provider to part of Generation Life's environment; Qilin ransomware group listed the insurer in May 2026 with no published samples

References