Included in the information exfiltrated as a result of the incident were names, tax identification numbers, and Social Security numbers, with a subset of individuals also having their bank account information, driver's license numbers, passport numbers, medical details, routing numbers, health insurance policy details, and life and annuity policy data exposed.
Investigation into the incident revealed that infiltration of Change Healthcare's employee systems through stolen credentials without multi-factor authentication enabled the eventual compromise of the firm's network with ransomware.
Autobell disclosed in a statement that its employees and customers may have had their full names, addresses, Social Security numbers, driver's license numbers, tax identification numbers, passport numbers, medical details, health insurance information, and financial details exfiltrated due to the incident.
Investigation into the incident conducted by a third party revealed that attackers may have accessed insurance practice files kept in a network location, said the insurer in breach notification letters.
Organizations would be barred from conducting direct sales of personal information to entities that are at least 50% owned by or located in a country of concern, contractors' foreign employees, and foreign individuals in a country of concern.
Infiltration of a laptop enabled attacker access to Transak's third-party know-your-customer vendor, facilitating the exposure of clients' names, birthdates, driver's license data, passports, and selfies, but not their financially sensitive details.
Also included in the data purportedly stolen from Country Inn & Suites were credit card information, billing details, internal emails, messages, incidents, and calendar details of previous and upcoming bookings.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.