The non-profit blood donation organization, OneBlood, has confirmed that it has suffered a data breach affecting the personal information of blood donors. The breach was the result of a ransomware attack that took place last summer.

OneBlood first announced the attack on July 31, 2024, noting that the attackers had encrypted virtual machines and forced the organization to revert to using manual processes.
OneBlood is a blood supplier to more than 250 hospitals in the United States. The ransomware attack caused delays in blood collection, testing, and distribution, causing problems at some clinics.
See also: FunkSec: New “AI” ransomware with over 85 victims
Last week, OneBlood began sending data breach notifications to affected individuals, informing them that its investigation was completed on December 12, 2024.
The breach date was determined to be July 14, 2024. The attackers maintained access to OneBlood's network until July 29, one day after the organization discovered the breach.
“Our investigation determined that from July 14 to July 29, 2024, certain files and folders were copied from our network without authorization,” OneBlood’s data breach notification states. “The investigation determined that your name and social security number were included in the relevant files and folders,” the notification continues.
Although blood collection centers typically collect more information, such as phone numbers, email and physical addresses, demographic data and medical history, the exposed data is limited to names and SSNs, according to the notice.
However, this information can be used for identity theft and financial fraud.
See also: Cleo attacks: Clop ransomware gang blackmails 66 companies
To mitigate this risk, OneBlood has attached activation codes to the letter for a free one-year credit monitoring service.
Additionally, individuals affected by the OneBlood data breach should consider placing credit holds and fraud alerts on their accounts to prevent financial losses.

The number of people affected by the ransomware attack has not been disclosed.
The OneBlood breach highlights the growing threat of cyberattacks on healthcare organizations, which are often targeted because of the sensitive and valuable data they hold. Cybersecurity experts recommend that healthcare organizations invest in strong security measures, such as regular system updates, training employees on phishing scams, and implementing multi-factor authentication. These measures can help deter future attacks and protect data.
See also: Telefónica: Data breach affects thousands of employees and customers
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In addition to the implications for blood donors, a breach like this can also have serious consequences for the organization itself. The loss of trust and reputation can be devastating, along with potential legal action and fines. Therefore, it is vital for healthcare organizations to prioritize cybersecurity and take the necessary precautions to protect sensitive data.
Source: www.bleepingcomputer.com
