Rhode Island has revealed that the recent breach of the RIBridges system (managed by Deloitte) was carried out by the ransomware gang Brain Cipher and led to a breach of resident data.

RIBridges is used in Rhode Island to administer and deliver public assistance programs.
The incident was discovered on December 5, 2024. Deloitte's investigation indicates that it is highly likely that files with personal information and other data were stolen.
“ On December 13, 2024, Rhode Island was notified by the vendor, Deloitte, that there was a major security threat to the RIBridges system ,” the statement released by Rhode Island authorities on Saturday said
“In response, we proactively took the system offlineso that the State and Deloitte could work to address the threat and restore the system as soon as possible.“.
See also: Clop ransomware says it is behind Cleo attacks
Deloitte said it was likely that a cybercriminal had obtained files with residents' personal information.
The company later discovered the “malicious code” in the system and RIBridges was taken offline. As a result, citizens lost accounts their (both via the web portal and the mobile app).
The data breach affects applicants and beneficiaries of the following programs in Rhode Island:
- Medicaid
- Supplemental Nutrition Assistance Program (SNAP)
- Temporary Assistance for Needy Families (TANF)
- Child Care Assistance Program (CCAP)
- Health coverage purchased through HealthSource RI
- Rhode Island Works (RIW)
- Long-Term Services and Supports (LTSS)
- General Public Assistance (GPA) Program
- At HOME Cost Share
The investigation is ongoing but Deloitte says names, addresses, dates of birth, social security numbers and some banking information may have been exposed.
Affected households will receive a letter in the mail, and affected residents can call a dedicated hotline to learn more about the incident.
General recommendations given by Rhode Island authorities include resetting passwords, activating fraud alerts and credit freezes on bank accounts , and activating security measures provided by their banks.
Those who need to apply for any of the above programs can do so by following the instructions provided here.
See also: Electrica Group Romania: Lynx ransomware behind the attack
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Deloitte confirms ransomware attack
The notification of the Rhode Island residents' data breach comes after the ransomware group "Brain Cipher" claimed earlier this month to have attacked Deloitte and stolen data from the company.
A spokesperson initially dismissed these claims, saying the data came from a single customer's system outside their corporate network.
However, in a new communication from BleepingComputer with the company, it was confirmed that this was a Brain Cipher ransomware attack.
“Rhode Island’s RIBridges system is the ‘one client system’ impacted by the Brain Cipher data breach,” a Deloitte spokesperson confirmed.
Ransomware protection
Back up your data: One of the most effective ways to protect yourself from a attack is to regularly back up your data. This ensures that even if your data is encrypted by ransomware, you will have a safe copy that can be restored without paying the ransom.

Update your operating system and software: Out-of-date operating systems and software are vulnerable to cyberattacks. It is important to regularly update your devices with the latest security and software updates to prevent any vulnerabilities that could be exploited by ransomware.
Beware of suspicious emails and links: Ransomware attacks often start with a phishing email or malicious link. It is important to be cautious when opening emails from unknown senders. Also, do not click on suspicious links. These could lead to ransomware being installed on your device.
See also: Sichuan Silence accused of ransomware attacks
Use antivirus software: Installing reputable antivirus software on your devices can help you detect and prevent attacks . Be sure to update your antivirus software to ensure it is equipped to handle new threats.
Education: One of the most important steps to protect against ransomware is education. It is important to stay up to date on the latest types of ransomware and how they work. Organizations should also train their employees on how to identify and avoid potential attacks.
Implement strong passwords: Weak or easy passwords can make it easier for hackers to gain access to your devices and install ransomware. It's important to use strong and unique passwords and enable two-factor authentication whenever possible.
Use a VPN: A VPN encrypts your internet connection and provides an extra layer of security against ransomware attacks. This is especially important when using public Wi-Fi networks, which are often unsecured and vulnerable to attacks.
Source: www.bleepingcomputer.com
