US faces major cyber attack, more than 4 mn health data stolen after hackers hit IBM
The US authorities have disclosed that the cyber criminals have exploited a zero-day vulnerability in the MOVEit file-transfer software to steal sensitive medical and health information data of millions of Americans.
The Colorado Department of Health Care Policy and Financing (HCPF) said it had fallen victim to the MOVEit mass hacks. Over four million patients’ data have been stolen by the criminals.
The department in a statement said that the data was compromised as IBM “uses the MOVEit application to move HCPF data files in the normal course of business.”
“IBM, a third-party vendor contracted with HCPF, uses the MOVEit application to move HCPF data files in the normal course of business,” said the department.
“Progress Software publicly announced that the MOVEit problem was the result of a cybersecurity incident, which impacted many users around the world, including IBM. No HCPF or State of Colorado systems were affected by this issue,” it added.
Following the notification from IBM regarding the impact of the MOVEit incident, The Colorado department started an investigation to ascertain whether the incident impacted its own systems. It is also to determine whether Health First Colorado or CHP+ members’ protected health information was accessed by an unauthorised party.
“The investigation identified that certain HCPF files on the MOVEit application used by IBM were accessed by the unauthorised actor. These files contained certain Health First Colorado and CHP+ members’ information,” the department revealed.
The information that could have been subject to unauthorised access includes name, Social Security number, medical information, and health insurance information.
The HCPF acknowledged the fact that around 4.1 million individuals are affected.
IBM has yet to publicly confirm that it was affected by the MOVEit mass hacks.
The US government services contracting company. Maximus has confirmed in July that hackers exploited a vulnerability in MOVEit Transfer to access the protected health information of 8 to 11 million individuals.
Maximus is a contractor that manages and administers federal and local government-sponsored programmes, as well as student loan servicing.
This is believed to be the largest healthcare data breach of the year and the most serious to result from the MOVEit mass-hackings.
In the US Securities and Exchange Commission (SEC) filing, Maximum revealed that the data was stolen by exploiting a zero-day vulnerability in the file transfer application.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.