Top food delivery service Purfoods leaks 1.2 million users medical and personal data

security
(Image credit: Shutterstock / binarydesign)

Food delivery business Purfoods has revealed it suffered a ransomware attack in which sensitive data on more than a million customers may have been stolen.

The company behind the "Mom's Meals" line notified 1,237,681 individuals of a cyberattack that happened in mid-January 2023. The notification doesn’t say which threat actor was behind the attack, but stresses the possibility of the theft of sensitive data.

"Because the investigation also identified the presence of tools that could be used for data exfiltration, Purfoods was not able to rule out the possibility that data was taken from one of its file servers," the company said.

Social Security Numbers at risk

A third-party incident response company, which was later hired to help address the aftermath of the attack, concluded that the data the attackers may have taken includes customer names, Social Security Numbers, driver’s licenses and state identification numbers, financial accounts, and payment card information (this also includes security codes, access codes, passwords, or PINs). Furthermore, the database included medical information, health information, and birth dates.  

Purfood’s unique selling proposition includes preparing health-focused meals, particularly its Mom’s Meals line, in which it teamed with more than 500 health providers to deliver refrigerated meals to people covered by Medicare and Medicaid. 

Purfoods has been silent on whether the company knows the name of the threat actor, or the amount of money demanded, but it did say that it notified law enforcement of the breach, and started implementing “additional safeguards” and more employee training to minimize the chances of such an incident repeating. It will also be providing free credit monitoring to affected customers. 

It also shared more information on how to protect against identity fraud and wire fraud, just in case.

Via: The Register

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A person's fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
Blood donation firm reveals donor personal data stolen in cyberattack
Data breach
Top medical billing firm says data breach hit 360,000 users
ID theft
Over a million patients potentially hit after another US healthcare provider hit by cyberattack
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Lock on Laptop Screen
United Healthcare data breach may have affected 190 million Americans
ransomware avast
The biggest addiction treatment provider in the US says it was hit by data breach
Latest in Security
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Security
Broadcom releases fixes for multiple VMware security flaws
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Latest in News
CorelDraw Go homepage showing design examples
Adobe arch-rival unveils online graphic design tool for beginners - and yes, it has a subscription
OnePlus Watch 3
Good news for OnePlus fans as it confirms the OnePlus Watch 3 will get three years of updates, not two
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Portrait of African-American teenage boy studying at home or in college dorm and using laptop, copy space
Windows 11’s Notepad gets AI-powered ‘Rewrite’ feature, but not everyone’s going to be happy about it
Pac-Man x PowerA promotional image.
Special edition Pac-Man Nintendo Switch and Xbox accessories from PowerA are on the way
Close up of PS5 DualSense controller leaning on a PS5
Sony goes full Xbox Insider with new Beta Program at PlayStation initiative, offering the testing of new games and features before release