HomeSecurityIBM: MOVEit health data stolen in DSS breach

IBM: MOVEit health data stolen in DSS breach

IBM: MOVEit health data stolen in DSS breach

The Missouri Department of Social Services is warning that protected Medicaid healthcare information was exposed to a data breach following an IBM MOVEit data theft attack.

See also: NATO: Investigates allegations of data theft by SiegedSec hackers

The attack was carried out by the Clop ransomware, which began breaching MOVEit Transfer servers on May 27 using a zero-day vulnerability identified as CVE-2023-34362.

These attacks allowed the perpetrators to steal data from more than 600 companies worldwide, including corporations, educational institutions, federal government agencies, and local government agencies.

The ransomware gang is expected to earn $75-100 million from these attacks.

Suggestion: The BlackCat ransomware group has upgraded its technique

Missouri health data exposed

Yesterday, the Missouri Department of Social Services (DSS) disclosed a data breach that exposed health information related to Medicaid services in the state. The breach occurred with IBM Consulting (IBM) and involved Progress Software’s MOVEit Transfer software. IBM is a vendor that provides services to DSS, and the data vulnerability did not directly impact any DSS systems, but it did impact data owned by DSS. IBM confirmed to BleepingComputer that the MOVEit Transfer server was compromised in these attacks, allowing the data to be stolen. After analyzing the stolen data, DSS confirmed that it contained protected health information for Medicaid participants in Missouri.

IBM MOVEit: Health information stolen in breach

The information involved in this incident may include an individual’s name, department customer number (DCN), date of birth, potential eligibility or coverage status, and medical claims information. The agency told BleepingComputer that the investigation revealed that only two Social Security numbers were exposed and that no banking information was found. DSS warns that due to the size of the stolen records and how they were formatted, it may take some time to analyze the data and fully determine the scope of the data breach. However, DSS is sending out alerts to all Missouri Medicaid participants who enrolled in May 2023 as a precaution. The agency suggests that individuals freeze their credit to prevent perpetrators from opening new accounts or borrowing money in their name, and recommends monitoring credit reports for unusual activity.

MOVEit Transfer attacks have also affected other state agencies, such as the Louisiana and Oregon Departments of Motor Vehicles, which warned in June that millions of state IDs had been stolen.

Read also: Norwegian Government: Its ICT platform was breached

source of information:bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS