HomeSecurityMCNA Dental: Data breach affects 8.9 million people

MCNA Dental: Data breach affects 8.9 million people

Managed Care of North America (MCNA) Dental has posted a data breach notification on its website, informing nearly nine million patients that their personal data has been compromised.

See also: How does the new Hot Pixels attack steal data?

MCNA Dental

MCNA Dental is one of the largest providers of government-funded Medicaid and CHIP dental care and oral health insurance in the US.

In a statement released on Friday, MCNA said it became aware of unauthorized access to its computer systems on March 6, 2023, and that the investigation revealed that hackers had first gained access to MCNA's network on February 26, 2023.

See also: Qbot malware hijacks Windows WordPad to evade detection

During this period, hackers stole data containing the following information for nearly nine million patients.

  • Full name
  • Address
  • Date of birth
  • Phone number
  • E-mail
  • Social Security Number
  • Driving license number
  • Government-issued ID number
  • Health insurance (plan information, insurance company, member number, Medicaid-Medicare ID numbers)
  • Accounts and insurance claims

The notification filed with the Maine Attorney General's Office says the breach affected 8,923,662 individuals, including patients, parents, guardians and guarantors.

MCNA said it has taken all appropriate steps to remediate the situation and enhance the security of its systems to prevent similar incidents in the future. It has also contacted law enforcement to help prevent the misuse of any stolen information.

However, not all affected individuals will receive a notice, as MCNA does not have everyone's current addresses; therefore, the organization has posted a substitute notice on IDX, which will remain online for 90 days.

In the said announcement, citizens can also find an extensive list of over a hundred healthcare providers indirectly affected by this incident. However, it is not clear whether these entities will publish separate announcements regarding the breach.

See also: Giant company ABB reveals data breach after ransomware attack

LockBit took responsibility for the attack

The LockBit ransomware claimed responsibility for the cyberattack on MCNA on March 7, 2023, when it published the first samples of data stolen from the healthcare provider.

LockBit threatened to publish 700 GB of sensitive and confidential information allegedly leaked from MCNA's networks unless they were paid $10 million.

On April 7, 2023, LockBit published all of its data on its website, making it available for download by anyone.

As the data is likely in the hands of other threat actors, all affected users should monitor their credit reports for signs of fraudulent activity and identity theft.

Additionally, users should be wary of targeted phishing emails that use the leaked data to trick recipients into revealing additional sensitive information, such as credentials.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS