Included in the information exfiltrated as a result of the incident were names, tax identification numbers, and Social Security numbers, with a subset of individuals also having their bank account information, driver's license numbers, passport numbers, medical details, routing numbers, health insurance policy details, and life and annuity policy data exposed.
Investigation into the incident revealed that infiltration of Change Healthcare's employee systems through stolen credentials without multi-factor authentication enabled the eventual compromise of the firm's network with ransomware.
Ever heard someone say, "the attacker only has to be right once, but the defender has to get it right every time"? On this episode, we'll dispel that myth. There is some truth to the saying, but only with regards to initial access to the target's environment. Once on the inside, the attacker's advantage flips to the defender. Call it the 'Home Alon...
Autobell disclosed in a statement that its employees and customers may have had their full names, addresses, Social Security numbers, driver's license numbers, tax identification numbers, passport numbers, medical details, health insurance information, and financial details exfiltrated due to the incident.
Such a demand from Rhysida, which has an Oct. 30 deadline, comes a week after Easterseals disclosed in a filing with the Office of the Maine Attorney General that 14,855 individuals had their information, including their full names, addresses, Social Security numbers, driver's licenses, passports, and medical and health details, exfiltrated as part of the April 1 attack.
Investigation into the incident conducted by a third party revealed that attackers may have accessed insurance practice files kept in a network location, said the insurer in breach notification letters.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.