HomeSecurityPfizer: patient data of the large pharmaceutical company was exposed

Pfizer: patient data of the big pharmaceutical company exposed

The world-renowned pharmaceutical company Pfizer Inc.appears to have suffered a data breach that left the information of many of its patients exposed in an unsecured cloud.

Pfizer

Researchers from vpnMentor discovered the exposed data yesterday in a misconfigured Google Cloud storage bucket. The data included hundreds of conversations between Pfizer's automated customer support software and people using its prescription drugs, including Lyrica , Chantix , Viagra , and cancer drugs like Ibrance and Aromasin .

But in addition to the conversations, the files also included personal medical information, as well as full names, home addresses and email addresses, which could be used by hackers to target patients with phishing campaigns.

“Hackers could easily trick victims by impersonating Pfizer customer service and reporting conversations that took place between them,” the researchers explained. “For example, many people were asking about prescriptions and other information. Such circumstances give cybercriminals a great opportunity to pretend to be from Pfizer and ask for credit card information to proceed with the medications.”

But beyond the financial benefit of a phishing, the researchers warned that there is also a risk of using the data to target patients with malware or even ransomware. If hackers were to use the personally identifiable information to trick a patient into providing more information, the combined data could be used for fraud, including identity theft, potentially destroying a person's financial well-being.

Pfizer: patient data of the big pharmaceutical company exposed

Most worryingly, the data remained exposed for months after its discovery. The researchers contacted Pfizer twice in July but received no response, before attempting to contact the company again on September 22. Finally, on the third attempt, they received a response and the data was taken down on September 23.

Pfizer has not made any announcement regarding the incident.

Pfizer could face legal action for the data breach. If any of the patients were California residents, they could use the Privacy Shield Act, which gives consumers the right to sue in the event of a data breach caused by a company’s failure to implement adequate security procedures.

This is not the first time that data from this company has been exposed. Pfizer has already had three data breaches to its credit, between 2007 and 2019.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS