Accellion breach exposed data from patients at major Michigan hospital system
Full article526 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
It's the latest in a long list of victims.
A major Michigan hospital system on Friday notified roughly 1,500 patients that their information may have been exposed as a result of a hack against file-sharing service Accellion.
The law firm Goodwin Proctor notified Beaumont Health in February that patient data shared by the hospital with legal counsel may have been entangled in the wide-reaching hack through the firm’s use of Accellion. Beaumonth Health is a network of health facilities that reported $4.58 billion in total revenue for 2020.
A follow-up investigation by Beaumont found that impacted patient health data included patient name, procedure name, physician name, internal medical record number and dates of service. No patient financial information was impacted, the hospital stated in a press release.
Beaumont Health joins a list of at least 11 healthcare organizations that were affected by a December breach of the file sharing service Accellion. Two of the victims, Kroger Pharmacy and healthcare insurer Centene, both had more than a million individuals’ data exposed by the hack. The incident, which also ensnared Qualys and a number of universities, was the work of a pernicious ransomware gang that has demanded extortion fees from unwitting victims, FireEye previously found
Cybercriminals exploited multiple vulnerabilities in Acellion’s software late last year, allowing them to infiltrate the company’s file-sharing tool to gather information from the company’s customers. The group unleashed a wave of extortion attempts against victims in late January, threatening to share their stolen data if they didn’t pay up.
Nearly nine months since the breach, the Accellion hack continues to claim a growing number of victims across industries. Victims of the attack also include Morgan Stanley, law firm Jones Day and Canadian plane manufacturer Bombardier.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/accellion-breach-exposed-data-from-patients-at-major-michigan-hospital-system/