A major American health insurance company, CareFirst BlueCross BlueShield, revealed that it fell victim to a cyber attack that affected approximately 1.1 million people.
The attack, which took place last June, targeted a single database containing information about CareFirst members and others who had access to its websites and services, the company said on Monday.
The nonprofit organization has 3.4 million members, most of whom reside in the surrounding areas of Maryland, Washington, DC, and Northern Virginia.
"We were the target of a cyber attack," said Chet Burrell, the company's CEO, in a video posted on the company's website.
CareFirst said customer names, dates of birth, usernames, email addresses and subscriber ID numbers may have been stolen. The database did not contain Social Security numbers, medical information or financial information, it said. And members' passwords were encrypted and stored on a separate system, CareFirst said.
The disclosure underscores the importance of security, and reminds us that this is at least the third major healthcare company to be targeted in a data breach this year. Security experts warn that medical data is increasingly being targeted by hackers.
Medical data is valuable to cybercriminals because they can use the information for fraud, or for more sophisticated purposes, such as spying on nation-states.
Computer security experts say the attacks against Anthem and Premera were carried out in a similar manner and tactic. In both cases, experts found evidence that the attackers had set up domain names with slightly distorted names of these companies.

