A data protection incident occurred at uniVersa Lebensversicherung, uniVersa Krankenversicherung, and uniVersa Allgemeine Versicherung, where an AI crawler was able to access data. According to uniVersa, this was only possible for a few hours. The reason is said to have been an IT transition on July 7, 2026. Several readers, who were informed by the company in recent days, had contacted heise online regarding the incident. The letter from uniVersa mentioned OpenAI. The AI provider was reportedly asked not to use the retrieved data and to delete it completely. IT forensic experts from uniVersa are currently investigating the incident.

According to a company spokesperson, the affected server “contained general personal data such as names and addresses, as well as contract data like insurance numbers and tariff information.” The company does not disclose how many customers are affected. For some customers, “bank details (IBAN and BIC) were also” impacted. However, “particularly sensitive information such as health, login, or credit card data, as well as the central administration and data systems and the customer portal,” were not impacted.

According to Universa, the incident was discovered “as part of internal security controls.” The unwanted access to the “individual server [...] was immediately shut down.” Furthermore, the company “engaged external forensic experts to clarify the matter as quickly as possible.” Additional security measures have also been implemented, and customer service is available for those impacted.