HomeSecurityPhishing incident causes data breach at West Virginia hospitals

Phishing incident causes data breach at West Virginia hospitals

A hospital system in West Virginia suffered a data breach as a result of a phishing attack, which gave hackers access to several email accounts.

phishing

See also: Meta: Taking legal measures to combat phishing attacks

Monongalia Health System – which operates Monongalia County General Hospital Company and Stonewall Jackson Memorial Hospital Company – said hackers accessed multiple email accounts from May 10 to Aug. 15. Those accounts contained sensitive information from patients, providers, employees and contractors.

The company completed its investigation into the incident on October 29, finding that the attack stemmed from a phishing incident carried out via email.

“Mon Health was first made aware of the incident after a vendor reported that they had not received payment from Mon Health on July 28, 2021. In response, Mon Health immediately launched an investigation, through which it determined that unauthorized individuals had gained access to a Mon Health contractor email account and sent emails from the account in an attempt to obtain funds from Mon Health via fraudulent bank transfers,” the company explained.

“Upon learning of this, Mon Health secured the contractor’s email account and reset the password, notified law enforcement, and a third-party forensics firm was brought in to assist in the investigation.”

See also: Phishing attacks impersonate Pfizer

The attack did not include information from their other hospitals, such as Mon Health Preston Memorial Hospital and Mon Health Marion Neighborhood Hospital.

phishing

The company claims that "the purpose of the unauthorized access to the email accounts was to obtain funds from Mon Health through fraudulent bank transfers and to commit a phishing scheme, not to access personal information.".

Mon Health began sending breach notification letters to victims on December 21 and said they could call a call center without being charged to be notified of the incident.

See also: New study on phishing reveals some interesting findings

Dozens of healthcare organizations have had to send breach notification letters to patients due to cyberattacks or ransomware that exposed sensitive data.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS