Johnson & Johnson Health Care Systems (“Janssen”) has notified CarePath customers that their sensitive information has been leaked in a third-party data breach involving IBM.
See also: North Korean hackers target security researchers using zero-day bug

IBM is a technology services provider for Janssen. Specifically, it manages the CarePath application and the database that supports its operations.
CarePath is an app designed to help patients access Janssen medications, offer discounts and savings tips on eligible prescriptions, provide insurance guidance, and alert them to refills and refills.
According to the announcement on Janssen's website, the pharmaceutical company was made aware of a previously undocumented method that could provide unauthorized access to users in the CarePath database.
The company notified IBM, which immediately patched the security flaw and launched an internal investigation to assess whether anyone exploited the flaw.
See also: iMessage: Zero-click exploit infects iPhones with spyware
Unfortunately, the investigation completed on August 2, 2023 showed that unauthorized users gained access to the following CarePath user details:
- Full name
- Contact information
- Date of birth
- Health insurance information
- Pharmaceutical information
- Information about patients' medical condition
The report affects CarePath users who signed up for Janssen's online services before July 2, 2023, which may indicate that the breach occurred on that date or that the compromised database was a backup.
Social Security numbers and bank account data were not stored in the compromised database, so these critical details have not been leaked.
The pharmaceutical company also clarified that this safety incident does not affect Janssen Pulmonary Hypertension patients.
Compromised data can support highly effective phishing, scamming, and social engineering attacks, and considering the value of medical data, there is a high probability that it will be sold at a high price on darknet markets.
IBM has issued a separate statement about the incident stating that there is no indication of abuse of the stolen data. However, IBM urges Janssen CarePath users to remain vigilant and carefully monitor their account statements for suspicious activity.
See also: Google Looker Studio abused in cryptocurrency phishing attacks
IBM is also among the hundreds of entities breached by the Clop ransomware earlier this year, when the notorious hackers exploited a zero-day vulnerability in the MOVEit Transfer used by many organizations worldwide.
A few weeks ago, the Colorado Department of Health Policy and Financing (HCPF) notified four million people that their personal and medical data was leaked due to a breach at IBM.
Information source: bleepingcomputer.com
