How attackers exploited a zero-day vulnerability to steal data from an insurance industry organization