Attack on healthcare provider exposes personal data of more than 4 million customers

Best practice management software
Image Credit: Pixabay (Image credit: Image Credit: Pixabay)

Less than a week after the news of the data breach at Zoll Medical, it's been revealed that hackers managed to breach healthcare provider Independent Living Systems (ILS)  and steal sensitive data from millions of users in July 2022. 

That's according to a notification filed with the Office of the Maine Attorney General (via BleepingComputer) by ILS earlier this week.

Per that notification, the company said that, during the attack, sensitive data on 4.2 million individuals were taken, including full names, Social Security numbers, taxpayer identification numbers, medical information, and health insurance information.

Customers notified

“Through its response efforts, ILS learned that an unauthorized actor obtained access to certain ILS systems between June 30 and July 5, 2022,” the notice reads.

“During that period, some information stored on the ILS network was acquired by the unauthorized actor, and other information was accessible and potentially viewed.”

This means that the stolen data can now potentially be sold on the dark web, used in phishing and social engineering attacks, or in cases of identity theft

The company said it had already notified the affected individuals, and offered one year free identity protection services, courtesy of Experian. 

Some details remain unknown at this time. We don’t know who the threat actor behind the attack is, or whether this was a ransomware attack. We also don’t know how the attackers compromised ILS’ networks - if a user inadvertently shared their login credentials, or if a zero-day vulnerability was abused through malware

Cybercriminals usually steal sensitive data while encrypting target endpoints, and then threaten to expose that data on the internet unless the payment is made. 

For Jocelyn Houle, Senior Director, Data Governance at Securiti, an attack on a healthcare organization isn’t surprising, but it does highlight the need to make data management, privacy, and security - a top priority. 

“AI & ML techniques to automate data management processes are becoming an essential step to mitigating the risk of the exposure of personal health information (PHI)."

"Automating policies by locating, protecting, and managing PHI reduces the risks of a breach, and coupled with controls such as least privilege access and techniques such as data masking, organizations can minimize exposure and damage in case of an attack." 

"Implementing a privacy management software also helps by providing cross-system visibility to identify insider threats and prevent threat actors from accessing healthcare organizations’ networks.”

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
healthcare
Top US health provider tells 882,000 patients they were hit in August 2023 breach
ID theft
Over a million patients potentially hit after another US healthcare provider hit by cyberattack
healthcare
Over a million clinical records exposed in data breach
Lock on Laptop Screen
United Healthcare data breach may have affected 190 million Americans
Data breach
Top medical billing firm says data breach hit 360,000 users
A person's fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
Blood donation firm reveals donor personal data stolen in cyberattack
Latest in Security
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Latest in News
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
Four operators survey Verdansk. One holds a sniper rifle, one binoculars, another holds is landing with their parachute, while the last wears a skull mask
New Call of Duty: Warzone trailer shows a beautiful rebuilt Verdansk, but some fans want more: 'it won't be the same unfortunately'
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog
The Meta Quest 3 and controllers on their charging station which is itself on a wooden desk next to a lamp
Forget Android XR, I've got my eyes on Vivo's new Meta Quest 3 competitor as it could be the most important VR headset of 2025
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS