Skip to content

Metropolitan Life Insurance

Disclosed Nov 1, 20169 years ago4,220 affectedConfirmed

Official notice

Metropolitan Life Insurance Company (MetLife), the covered entity (CE) reported that an unauthorized individual gained access to 4,420 online customer accounts through an email phishing scheme. The protected health information (PHI) involved included names, addresses, health policy numbers, and account information. MetLife provided breach notification to HHS, individuals affected by the breach, and posted a warning notice on its website educating its customers of the risk of phishing attacks and provided customers with free credit monitoring. During OCR’s investigation, OCR determined that the incident did not constitute a breach, as the incident reported by MetLife did not involve a compromise to its own computer system. Specifically a phishing email was sent externally to MetLife customers and non-customers, which some MetLife and non-MetLife customers responded to providing their account authentication information which gave the unauthorized individual access to their accounts.

What is known

People affected4,220 (as reported to HHS)
DisclosedNov 1, 2016
HappenedSep 9, 2016
AttackInsider
Data exposedNames, Health
SectorInsurance · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
Indiana AGresidents of INNov 1, 20163
HHS archivetotalJul 19, 20174,220

Other breaches at Metropolitan Life Insurance

BreachAffected
Disclosed Mar 9, 2026Mar 96 months agoUnknown
Disclosed Mar 28, 2024Mar 28, 20242 years ago9,702
Disclosed Aug 10, 2020Aug 10, 20206 years agoUnknown
Disclosed Nov 16, 2018Nov 16, 20187 years ago104
History of this record
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 4220 · backfill source
  • 2026-09-25 · summary: empty to Metropolitan Life Insurance Company (MetLife), the covered entity (CE) reported that an unauthorized individual gained access to 4,420 online customer accounts through an email phishing scheme. The protected health information (PHI) involve · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Metropolitan Life Insurance

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.