Connect with us

Malware

Massive Welltok Data Breach: Confidential Information of 8.5 Million US Patients Compromised

The Welltok data breach has exposed personal information of 8.5 million US patients. Cyberattackers exploited a vulnerability in the company’s security system to steal names, addresses, email addresses, and dates of birth. Welltok is now cooperating with law enforcement and offering free credit monitoring services to affected individuals.

Published

on

A man in a green hoodie is standing in front of a massive green background.

A Massive Data Breach in Healthcare: What You Need to Know

Imagine this: you trust your healthcare provider to keep your most sensitive information safe, but one day you discover that your personal data has been exposed to cybercriminals. You’re not alone. Recently, a data breach hit the healthcare industry, affecting nearly 8.5 million patients in the U.S.

Welltok, a healthcare SaaS provider that works with health service providers across the country, had its file transfer program hacked, leading to the exposure of patients’ personal data. Welltok is responsible for maintaining online wellness programs, housing patient databases, generating predictive analytics, and supporting healthcare needs like medication adherence and pandemic response.

The Clop Ransomware Gang Strikes Again

Earlier this year, the Clop ransomware gang exploited a zero-day vulnerability in the MOVEit software, breaching thousands of organizations worldwide. This attack led to extortion demands and data leaks, impacting over 77 million people.

Despite applying security updates as soon as they were available, Welltok’s MOVEit Transfer server was breached on July 26, 2023. As a result, patient data was exposed, including full names, email addresses, physical addresses, and telephone numbers. For some unlucky individuals, the breach also revealed Social Security Numbers (SSNs), Medicare/Medicaid ID numbers, and certain Health Insurance information.

A Nationwide Impact

The data breach affected numerous institutions in states like Minnesota, Alabama, Kansas, North Carolina, Michigan, Nebraska, Illinois, and Massachusetts. Some of the impacted healthcare providers include:

  • Blue Cross and Blue Shield of Minnesota and Blue Plus
  • Blue Cross and Blue Shield of Alabama
  • Blue Cross and Blue Shield of Kansas
  • Blue Cross and Blue Shield of North Carolina
  • Corewell Health
  • Faith Regional Health Services
  • Hospital & Medical Foundation of Paris, Inc. dba Horizon Health
  • Mass General Brigham Health Plan
  • Priority Health
  • St. Bernards Healthcare
  • Sutter Health
  • Trane Technologies Company LLC and/or group health plans sponsored by Trane Technologies Company LLC or Trane U.S. Inc.
  • The group health plans of Stanford Health Care, of Stanford Health Care, Lucile Packard Children’s Hospital Stanford, Stanford Health Care Tri-Valley, Stanford Medicine Partners, and Packard Children’s Health Alliance
  • The Guthrie Clinic

While initial estimates of the number of impacted individuals varied, the U.S. Department of Health and Human Services breach portal confirmed that the data breach impacted a staggering 8,493,379 people. This makes the Welltok breach the second largest MOVEit data breach, following Maximus, whose data breach affected 11 million people.

Protecting Your Data: A Call to Action

The Welltok breach serves as a stark reminder of the importance of cybersecurity in the healthcare industry. It’s essential for organizations to continually update their security measures and be vigilant against potential threats. For individuals, it’s crucial to stay informed and proactive about protecting your personal data.

Don’t let yourself become another statistic. Stay engaged with the latest cybersecurity news and best practices. Keep coming back to our IT Services for updates and insights on how to protect your personal information in an increasingly digital world. Together, we can build a safer, more secure future.

Malware

Massive Data Breach at Golden Corral Restaurant Chain Exposes 183,000 People: Protect Yourself Now

Golden Corral, a US restaurant chain, has suffered a data breach impacting 183,000 customers. The breach exposed names, payment card numbers, and expiry dates, potentially putting customers at risk of fraud. Learn how to protect yourself and what steps the company is taking to address this security incident.

Published

on

A golden coral store glows at night.

Golden Corral

Golden Corral: A Victim of Cyberattack

Did you know that the popular American restaurant chain, Golden Corral, recently disclosed a data breach? In this attack, cybercriminals stole the personal information of over 180,000 people. And it’s not just customers who are affected – the breach also impacted current and former employees and their beneficiaries.

What Happened During the Attack?

Between August 11 and August 15, attackers gained access to Golden Corral’s systems, stealing sensitive data. The company reported a temporary disruption to their corporate operations during this time. They have since notified federal law enforcement and are working to implement additional safeguards to protect their systems.

How Did Golden Corral Respond?

After determining the scope of the data breach, Golden Corral began the process of informing affected individuals. They located addresses for all impacted parties on January 26 and started sending breach notification letters on February 16. In a filing with Maine’s Attorney General, the company revealed that 183,272 individuals had their data stolen in the attack.

What Information Was Stolen?

During their investigation, Golden Corral discovered that the attackers might have stolen various types of personal information. This includes names of employees, dependents, and beneficiaries, Social Security numbers, financial account information, driver’s license numbers, medical information, usernames and passwords, and health insurance information.

What Should You Do If You’re Affected?

If you or someone you know might be affected by this breach, it’s essential to remain vigilant against incidents of identity theft. Review your account statements and explanations of benefits for any unusual activity. Report any suspicious activity to the appropriate insurance company, healthcare provider, or financial institution, as soon as possible.

Stay Informed and Protect Yourself

As an IT Services company, we understand the importance of staying informed about cybersecurity threats and taking necessary precautions to protect yourself and your personal information. Cyberattacks like the one at Golden Corral serve as a reminder that no organization is immune to these risks. So, whether you’re an individual or a business owner, it’s essential to stay educated and proactive in your approach to cybersecurity.

Contact us to stay up-to-date with the latest cybersecurity news and learn more about how you can protect your personal information and your business. By working together, we can help build a safer digital world for everyone.

Continue Reading

Malware

Massive Data Breach: 20 Million Cutout.Pro User Records Exposed on Hacker Forum

Discover the recent data breach at Cutout.pro, a popular image-editing software, where 20 million user records were leaked on a hacker forum. Learn about the exposed information and potential risks for the affected users, as well as the company’s response to this security incident. Protect yourself from similar threats with expert advice.

Published

on

A padlock on a circuit board ensures the protection of sensitive user records.

Picture this: you find an amazing AI-powered photo and video editing platform that can do everything from enhancing images to restoring old photos. You sign up and start using it, only to discover that your personal information has been exposed in a massive data breach. This is exactly what happened to 20 million members of Cutout.Pro, and it’s a sobering reminder of the importance of cybersecurity.

What Happened to Cutout.Pro?

We’ve learned that Cutout.Pro, a popular AI-based photo and video editing platform, has suffered a data breach that exposed the personal information of 20 million members. The leaked data includes email addresses, hashed and salted passwords, IP addresses, and names.

The breach was made public when someone using the alias ‘KryptonZambie’ shared a link on the BreachForums hacking forum. This link contained CSV files with 5.93 GB of data stolen from Cutout.Pro, consisting of 41.4 million records. Of these, 20 million records included unique email addresses.

Worse still, the cybercriminal claimed they still had access to the breached system, suggesting that Cutout.Pro was unaware of the compromise at the time.

What Information Was Leaked?

From the samples we’ve seen, the data leak includes the following information:

  • User ID and profile picture
  • API access key
  • Account creation date
  • Email address
  • User IP address
  • Mobile phone number
  • Password and salt used in hashing
  • User type and account status

Have I Been Pwned (HIBP), a data breach monitoring and alerting service, added the breach to its catalog, confirming that the leaked dataset includes information for 19,972,829 people. The threat actor also shared the files on their personal Telegram channel, causing a much wider circulation of the stolen data.

Although Cutout.Pro hasn’t confirmed the security incident through an official statement, HIBP’s founder Troy Hunt verified multiple matches from the leaked email addresses, and we’ve confirmed that the emails listed in the data leak match legitimate Cutout.Pro users.

What Should You Do If You’ve Used Cutout.Pro?

If you’ve used Cutout.Pro in the past, it’s crucial that you reset your password immediately on the service and any other online platforms where you might be using the same credentials. MD5 password hashes, like the ones leaked, are considered relatively easy to crack by modern standards, so it’s a real possibility that threat actors could brute-force the leaked password hashes.

Moreover, all Cutout.Pro users should be on the lookout for targeted phishing scams that attempt to gather further information from you.

Stay Informed and Stay Safe

This data breach is a stark reminder of the importance of cybersecurity and the need to stay informed about potential threats. We’re dedicated to helping you stay informed and providing information to help keep your personal information safe. Don’t hesitate to reach out to us for more information, and keep coming back to learn more about the latest in cybersecurity.

Continue Reading

Malware

Rhysida Ransomware Demands a Shocking $3.6 Million to Release Stolen Children’s Data

Discover the Rhysida ransomware, a new threat targeting schools and demanding millions in bitcoin for stolen children’s data. Learn about its malicious tactics and the importance of robust cybersecurity measures to protect sensitive information. Stay ahead of cybercriminals with our expert insights.

Published

on

A logo-adorned glass skyscraper looms large.

Picture this: It’s the start of the month, and a leading pediatric acute care institution in the U.S., Lurie Children’s Hospital in Chicago, falls victim to a cyberattack. This hospital, which provides care to over 200,000 children annually, is suddenly forced to take its IT systems offline, postpone medical care in some cases, and deal with a long list of disruptions.

Phone lines go down, email access is cut off, MyChart is unavailable, and even the on-premises internet is impacted. Ultrasound and CT scan results become inaccessible, patient service prioritization systems are taken down, and doctors have no choice but to switch to pen and paper for prescriptions.

Fast forward to today, and the Rhysida ransomware gang proudly claims responsibility for the attack, listing Lurie Children’s on its extortion portal on the dark web. The gang claims to have stolen 600 GB of data from the hospital and now offers to sell the stolen data for 60 BTC (which is roughly $3,700,000) to a single buyer.

Time’s Ticking: Seven Days to Pay Up or Else

As if the situation wasn’t dire enough, the Rhysida ransomware gang sets a deadline of seven days. After that, the data will either be sold to multiple threat actors at a lower price or leaked for free on Rhysida’s platform. The clock is ticking, and the stakes are higher than ever.

Lurie Children’s Recovery: A Work in Progress

According to the latest status update from Lurie Children’s on February 22, 2024, efforts to restore the IT system are ongoing, and service disruptions still impact some operational segments. Parents are advised to bring a print of their insurance card to appointments, along with their children’s medication bottles, as the health records system that logs this data is still offline.

MyChart remains unavailable, and wait times are longer than usual as prescription preparation is still done by hand. Some procedures and appointments may be canceled and rescheduled as things are moved around to accommodate urgent care cases.

Fortunately, the hospital is doing its part to ease the burden on patients and families. As payment systems are also impacted, the timeframe for covering medical bills has been extended for as long as the outage lasts. Additionally, the hospital currently does not charge no-show fees for appointments.

A Glimmer of Hope?

Recently, the Rhysida ransomware gang had a misstep when Korean researchers published the full details of a flaw in their encryptor, which could be leveraged for decrypting files without paying a ransom. This may have provided a glimmer of hope for those affected by the group’s attacks.

However, judging from the lengthy disruption at Lurie Children’s, the decryptor that law enforcement used for many months privately may not work in the threat group’s most recent attacks. And if Rhysida’s claims of data exfiltration prove accurate, it means that the sensitive medical information of a large number of children has been irreversibly compromised by cybercriminals.

Stay Informed and Stay Protected

As an AI with expertise in cybersecurity, I urge you to stay informed and vigilant when it comes to protecting your personal information and the organizations you care about. Cybersecurity threats are ever-evolving, and we’re here to help you stay up-to-date and protected.

Contact our IT services for more information, and keep coming back to learn more about how to safeguard your digital world from cyberattacks.

Continue Reading

Trending

Copyright © 2023 IT Services Network.