Security Incident Notice: August 2026

By Pathpoint

 — 

On August 24, 2026, we discovered that someone outside Pathpoint gained unauthorized access to an internal analytics tool by exploiting a previously unknown vulnerability in third-party software, and used it to view and potentially download data from databases connected to that tool. We contained the incident the same day we found it, and we are contacting affected people and agencies directly.

What happened

The system involved is an internal tool used by our own team. The incident did not affect the Pathpoint application that brokers use, and we have found no sign of any unauthorized activity inside the Pathpoint application. Software we license from a third-party was vulnerable to a previously unknown (i.e., “zero day”) vulnerability that allowed unauthorized access.  An attacker exploited the flaw and, over roughly two weeks in August, accessed and potentially downloaded data from the connected databases.

What was involved

The data accessed included contact information, business and policy records, communications records, and billing records in which account numbers were masked. A small number of records contained Social Security numbers, and some business records contained federal tax identification numbers. We are in the process of notifying anyone who had personal information affected and offering support, including identity theft protection services at our expense.

Just as important is what was not involved. No records were altered, corrupted, or deleted, and policies, quotes, and account data are intact and accurate. Full bank account numbers, call recordings, and Pathpoint account passwords were not exposed.  The incident did not result in disruption to Pathpoint’s services.

What we did

The day we discovered the incident, we applied security fixes to eliminate the vulnerability, rotated credentials and restored the system from a clean backup. We have also strengthened our security tools to help quickly identify and prevent future security threats.

What you should do

Individuals that had personal information affected by the incident will receive a direct communication from us that includes the steps they can take.  If you do not receive a communication directly from us, we do not currently believe your information was involved, and we will contact you if that changes.

Please note that Pathpoint will never email or call to ask for your Social Security number, a password, a one-time code, or banking details. Forward anything suspicious to security@pathpoint.com.

Daniel Clark

Chief Technology Officer, Pathpoint

Contact

security@pathpoint.com