Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • Technology

US government contractor says MOVEit hackers accessed health data of ‘at least’ 8 million individuals

  • July 27, 2023
Total
0
Shares
0
0
0

U.S. government services contracting giant Maximus has confirmed that hackers exploiting a vulnerability in MOVEit Transfer accessed the protected health information of as many as 11 million individuals.

Virginia-based Maximus contracts with federal, state, and local governments to manage and administer government-sponsored programs, such as Medicaid, Medicare, healthcare reform, and welfare-to-work. 

In an 8-K filing on Wednesday, Maximus confirmed that the personal information of a “significant number” of individuals was accessed by hackers exploiting a zero-day vulnerability in MOVEit Transfer, which the organization uses to “share data with government customers pertaining to individuals who participate in various government programs.”

While Maximus hasn’t yet been able to confirm the exact number of individuals impacted — something the company expects to take “several more weeks” — the organization said it believes hackers accessed the personal data, including Social Security numbers and protected health information, of “at least” 8 to 11 million individuals. If the latter, this would make the breach the largest breach of healthcare data this year — and the most significant data breach reported as a result of the MOVEit mass-hacks.

Maximus has not confirmed what specific types of health data were accessed and has not responded to TechCrunch’s questions. In its 8-K filing, the company said it began notifying impacted customers and federal and state regulators, adding that it expects the security incident to cost approximately $15 million to investigate and remediate. 

Clop, the Russia-linked data extortion group responsible for the MOVEit mass-hacks, claims to have stolen 169 gigabytes of data from Maximus, which it has not yet published. 

Maximus is one of just hundreds of organizations impacted by the MOVEit Transfer hacks to appear on Clop’s dark web leak site. This week alone, the ransomware group added a number of new victims, including accountancy giant Deloitte, and global sports betting provider Flutter, which owns Fox Bets and Poker Stars. 

In a statement given to TechCrunch, Deloitte spokesperson Sutton Meagher said that the company’s analysis of the incident “determined that our global network use of the vulnerable MOVEit Transfer software is limited,” adding that the company has “seen no evidence of impact to client data.”

Clop also recently listed accountancy firms PwC and Ernst & Young as its latest victims.

Flutter spokesperson Robert Allan told TechCrunch that the Dublin-headquartered organization “has been impacted” by the MOVEit mass-hacks and has “notified affected employees and customers.” Flutter, which claims to provide services to more than 18 million customers globally, declined to say how many individuals had been impacted or what types of data had been accessed.

Clop also this week listed Pensions Benefit Information, which provides pension plan management services to various industries. The organization has confirmed it was breached in a brief statement on its website but hasn’t said how many individuals have been impacted. Four of the organization’s clients — including CalPERS, CalSTRS, Genworth Financial, and Wilton Reassurance — have disclosed that the data of more than 4.75 million people had been accessed. 

According to the latest figures from cybersecurity company Emsisoft, more than 500 organizations have so far been impacted by the MOVEit mass-hacks, exposing the personal information of more than 34.5 million people.


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

GlossGenius raises $28M to expand its bookings and payments platform for beauty businesses

  • July 27, 2023
View Post
Next Article
  • News

The Sims-like open-world Life By You has had early access delayed into 2024

  • July 27, 2023
View Post
You May Also Like
View Post
  • Technology

Anthropic’s Dario Amodei on AI’s limits: ‘I’m not sure there are any’

  • September 21, 2023
View Post
  • Technology

New Forethought tool lets you build workflows with natural language

  • September 21, 2023
View Post
  • Technology

GitHub launches passkey support into general availability

  • September 21, 2023
View Post
  • Technology

Firebot is designed to scout burning builders before sending in firefighters

  • September 21, 2023
View Post
  • Technology

Qruise wants to build AI to automate quantum device development

  • September 21, 2023
View Post
  • Technology

Roblox cuts 30 on talent acquisition team as hiring slows

  • September 21, 2023
View Post
  • Technology

Secoda secures $16M to expand its data cataloging platform

  • September 21, 2023
View Post
  • Technology

Diligent raises $25 million to triple its nursing robot’s reach

  • September 21, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.