[BreachExchange] Hacker breached Massachusetts systems' emails for 6+ months; 200,000+ individuals affected

Terrell Byrd terrell.byrd at riskbasedsecurity.com
Thu Nov 11 13:41:05 EST 2021


https://www.beckershospitalreview.com/cybersecurity/hackers-breached-umass-memorial-s-emails-for-5-months-affecting-3-000-patients.html


Worcester-based UMass Memorial Health began notifying more than 200,000
patients and health plan participants that a hacker breached employee email
accounts containing their personal information, according to data the
health system shared with HHS on Oct. 15.

Three things to know:

On Jan. 27, a hacker breached a limited number of the health system's
employee email accounts, which contained the information of 209,048
patients and health plan participants, according to UMass Memorial Health's
news release.

The health system launched an investigation to determine the scope of the
breach. The investigation determined the hacker accessed the accounts
between June 24, 2020, and Jan. 7, 2021. The investigation was unable to
determine if the hacker viewed any emails or attachments in the accounts.

On Aug. 25, the health system identified which patients have been exposed
and what information was contained in the email accounts. Information that
was compromised includes names, Social Security numbers, medical-related
information and other data.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.riskbasedsecurity.com/pipermail/breachexchange/attachments/20211111/e75fde17/attachment.html>


More information about the BreachExchange mailing list