IT Security Incidents

Stay informed about real-world incidents that impact organizations and individuals. Get insights into data breaches, hacking attempts, and distributed denial-of-service (DDoS) attacks, along with expert analysis and recommended countermeasures.

Exposure of The Oncology Institute Patients' Data Linked to Third-Party Vendor Breach

Exposure of The Oncology Institute Patients’ Data Linked to Third-Party Vendor Breach

The Oncology Institute confirmed that patient data was potentially accessed following unauthorized access to its systems related to a cybersecurity incident at a third-party vendor affecting healthcare data processing and related services. SEC Filing Disclosure … Read more

Nuance Communications Employee Sentenced for Data Breach Violation

Nuance Communications Employee Sentenced for Data Breach Violation

A former employee of Nuance Communications has been sentenced for illegally accessing and copying the sensitive data of approximately 1.2 million Geisinger Health System patients after he was terminated from employment. Max Vance, 46 years … Read more

MediCopy Data Breach Impacts Deaconess Health System

MediCopy Data Breach Impacts Deaconess Health System

Deaconess Health System reported a data breach involving patient information shared with a third-party vendor, MediCopy, following unauthorized access to a cloud-based file-sharing platform. Incident Overview Deaconess Health System, based in Evansville, Indiana, disclosed a … Read more

Former Nuance Employee Pleads Guilty to Unauthorized Access of Geisinger Patient Records

Former Nuance Employee Pleads Guilty to Unauthorized Access of Geisinger Patient Records

A former Nuance Communications employee pleaded guilty in federal court to obtaining information from a protected computer without authorization after accessing and copying data associated with more than 1.2 million Geisinger Health System patient records. … Read more

Duly Health and Care Settles Data Breach Lawsuit for $3.1 Million

Duly Health and Care Settles Data Breach Lawsuit for $3.1 Million

HIPAA-covered entity, Midwest Physician Administrative Services, LLC doing business as Duly Health and Care agreed to a $3.1 million settlement to resolve class action litigation related to the use of website tracking technology that allegedly … Read more

More Than 14.7M Individuals Affected by Conduent Business Services Data Breach

More Than 14.7M Individuals Affected by Conduent Business Services Data Breach

Conduent Business Services located in New Jersey had earlier sent a breach report to the Oregon Attorney General about a hacking incident in 2024 that affected 10.5 million people across the country. This is one … Read more

Oracle Health Data Breach May Have Affected 80 Hospitals

Oracle Health Data Breach May Have Affected 80 Hospitals

The number of people impacted by Oracle Health’s hacking incident is not yet confirmed. The data breach may have impacted roughly 80 hospitals, though there is no report to the public yet of the listing … Read more

353 GB Data Stolen from Doctor Alliance

353 GB Data Stolen from Doctor Alliance

HIPAA business associate Doctor Alliance, based in Dallas, TX, is looking into an incident involving a hacker who stole 353 GB of data during a cyberattack in November. On or about November 7, 2025, a … Read more

Absolute Dental Notified Over 1.2 Million Individuals About Its Data Breach

Absolute Dental Notified Over 1.2 Million Individuals About Its Data Breach

A dental practice in Nevada, Absolute Dental, has more than 50 centers in Carson City, Las Vegas, Minden, Reno, and Sparks. It concluded its investigation associated with a February 2025 cyberattack and has announced that … Read more

87 Skilled Nursing Facilities Affected by Fundamental Administrative Services Data Breach

87 Skilled Nursing Facilities Affected by Fundamental Administrative Services Data Breach

Fundamental Administrative Services, LLC located in Sparks, Maryland, reported the potential compromise of the protected health information (PHI) of 56,235 individuals due to a cyberattack. The healthcare management services firm operates over 85 skilled nursing … Read more

Bone & Joint Clinic Pays $575,000 to Resolve Class Action Lawsuit

Bone & Joint Clinic Pays $575,000 to Resolve Class Action Lawsuit

Bone & Joint Clinic S.C. decided to resolve a class action lawsuit by paying $575,000. The lawsuit is associated with a security breach in January 2023 that had 105,094 affected patients and workers. HIPAA-covered entity, … Read more

Northwell Health Ex-Employee Secretly Recorded Videos of Patients in Toilets

Northwell Health Ex-Employee Secretly Recorded Videos of Patients in Toilets

Sanjai Syamaprasad, 47 years old, from Brooklyn, NY is an ex-employee of the Northwell Health Sleep Disorders Center who was indicted by the Nassau County District Attorney’s Office. Allegedly, Syamaprasad set up a hidden camera … Read more

Rhode Island Announces the Results of RIBridges Hacking Investigation

Rhode Island Announces the Results of RIBridges Hacking Investigation

The state of Rhode Island has published the results of the investigation conducted by cybersecurity company CrowdStrike regarding the hacking incident involving RIBridges, Rhode Island’s state benefit system. The Brain Cipher threat group was behind … Read more

Multiple Lawsuits Filed Against Southeast Series of Lockton Companies Over 1M-Record Breach

Multiple lawsuits were filed against Southeast Series of Lockton Companies (Lockton) based in Kansas City, Missouri, because of a data breach report submitted to OCR. The initial report was 1,706 people were impacted, but a … Read more

Email Account Breaches at Two Beacon Health System Business Associates

Email Account Breaches at Two Beacon Health System Business Associates

Beacon Health System, based in South Bend, Indiana, has reported two data breaches associated with two business associates. The non-profit health care system added two breach notices on its website. The incident at business associate … Read more

PHI Exposed Due to Orthodontic Practice Management Software Provider Data Breach

PHI Exposed Due to Orthodontic Practice Management Software Provider Data Breach

Orthodontic practice management software provider OrthoMinds, based in Alpharetta, Georgia, recently reported a security incident that occurred in November 2024, allowing unauthorized access to patients’ protected health information (PHI). According to forensic investigation, parts of … Read more

86,000 Records in Healthcare Employees Database Compromised Online

86,000 Records in Healthcare Employees Database Compromised Online

A health technology firm in New Jersey encountered a breach of its database online, resulting in the exposure of sensitive data. Anyone could freely access the database with no need for authentication. The database associated … Read more

Healthcare Organizations Targeted in 41% of 2024 Third-Party Breaches

Healthcare Organizations Targeted in 41% of 2024 Third-Party Breaches

According to new research, the healthcare industry is the most impacted by third-party breaches. Monitoring by Black Kite, a cyber risk intelligence and risk management software company, showed that 41.2% of third-party breaches occur in … Read more

Solara Medical Supplies Settles HIPAA Violations Paying $3M

Solara Medical Supplies Settles HIPAA Violations Paying $3M

The HHS’ Office for Civil Rights (OCR) has reported a settlement with Solara Medical Supplies, LLC to settle multiple HIPAA Rules violations. Solara Medical Supplies, LLC is a direct-to-patient supplier of medical products and a … Read more

43,000 UT Southwestern Medical Center Patients Impacted by Data Breach

43,000 UT Southwestern Medical Center Patients Impacted by Data Breach

UT Southwestern Medical Center (UTSW) in Texas submitted a breach report to the HHS’ Office for Civil Rights (OCR) involving an email-linked unauthorized access/disclosure incident that affected the protected health information (PHI) of about 43,048 … Read more

Kaye-Smith Pays $2 Million to Resolve Class Action Data Breach Lawsuit

Kaye-Smith Pays $2 Million to Resolve Class Action Data Breach Lawsuit

The marketing firm and mailing vendor, Kaye-Smith Enterprises, opted to settle a class action lawsuit associated with a cyberattack and data security breach in 2022. Hackers acquired access to its network, deployed ransomware for file … Read more

GoodRx to Pay $25 Million to Settle Tracking Technology Lawsuit

GoodRx to Pay $25 Million to Settle Tracking Technology Lawsuit

Telemedicine platform company and drug discounter GoodRx will pay $25 million to settle a consolidated class action lawsuit. When users became aware that GoodRx used website tracking tools on its platform and shared website visitor … Read more

Truepill Pays $7.5 Million To Settle Data Breach Lawsuit

Truepill Pays $7.5 Million To Settle Data Breach Lawsuit

Postmeds Inc., dba Truepill, an online pharmacy, has agreed to negotiate a class action lawsuit it faced due to a 2023 data breach that impacted 2,364,359 people. U.S. District Court Judge Haywood S. Gilliam gave … Read more

UMC Health System Ransomware Attack

UMC Health System Hit by Ransomware Attack

In late September 2024, the UMC Health System in Lubbock, Texas, suffered a ransomware attack that greatly affected its IT infrastructure. The attack forced the health system to divert ambulances and patients to other hospitals … Read more

U.S. Indicts Three Iranians in Trump Campaign Hack

The U.S. Department of Justice recently announced charges against three Iranian operatives accused of hacking into former President Donald Trump’s campaign and leaking confidential documents. The indictment details the hacking operations linked to Iran’s Islamic … Read more

CrowdStrike’s Apology and the Fallout from the Global IT Outage

The prominent cybersecurity company “CrowdStrike”, recently issued a public apology after a widespread IT outage caused by its Falcon Sensor software update brought many systems to a standstill. Affecting an estimated 8.5 million Windows PCs … Read more

Ransomware Attack on Ascension's Financial Recovery

Impact of the Ransomware Attack on Ascension’s Financial Recovery

Healthcare system Ascension based in St. Louis, MO encountered a ransomware attack in May 2024 that considerably impacted the company, both operationally and financially. Because of the attack, Ascension diverted ambulances, closed pharmacies, took down … Read more

Disney Phasing Out Slack After Massive Data Breach

In July 2024, The Walt Disney Company faced a cybersecurity breach when over 1TB of sensitive data was stolen from its internal Slack channels. The breach was carried out by the group ‘NullBulge,’ exposing confidential … Read more

Capita

High Court Battle Looms for Capita Over Major Data Breach in 2023

Nearly 8,000 individuals are set to join a High Court case against the outsourcing firm ‘Capita’ , following a cyberattack that occurred in March 2023. Barings Law, the Manchester-based legal firm representing the claimants, has … Read more

AI Industry Leaders to Combat Image-Based Sexual Abuse

The U.S. government has received a set of voluntary commitments from AI industry leaders aimed at addressing the issue of image-based sexual abuse, including non-consensual intimate images (NCII) and child sexual abuse material (CSAM). Big … Read more

Change Healthcare Data Breach Latest Update

In February 2024, Change Healthcare suffered a ransomware attack that exposed sensitive personal and medical data. This breach affected millions of Americans, potentially impacting up to one-third of the U.S. population. By mid-July 2024, Change … Read more

Flawed NetSuite Setup Leaves Customer Data Exposed

Thousands of Oracle NetSuite SuiteCommerce sites have been found vulnerable to exposing sensitive customer data due to misconfigured access controls on Custom Record Types (CRTs). This issue emanates from user misconfigurations rather than a flaw … Read more

The Full Breakdown of Delta’s IT Woes

Delta Air Lines is contending with the aftermath of an IT outage that disrupted its operations for several days in July, resulting in thousands of canceled flights and financial losses. The outage, which was caused … Read more

Global Disruption from CrowdStrike Falcon Sensor Update

An incident involving CrowdStrike’s Falcon Sensor software recently led to a global crash of millions of Windows devices. The root cause analysis conducted by CrowdStrike traces the issue back to a problematic content update, pointing … Read more

Alert: Chinese Hackers Exploit Zero-day Vulnerability in Cisco Routers

On July 2, 2024, Cisco issued a critical security alert regarding a major vulnerability in its routers exploited by Chinese hackers. The vulnerability, CVE-2023-20109, affects Cisco NX-OS software, allowing attackers to execute arbitrary commands with … Read more

Cyber espionage groups targeting critical infrastructure: The rise of ransomware attacks

A joint report from analysts at SentinelLabs and Recorded Future has studied two distinct activity clusters targeting government sectors and critical infrastructure globally between 2021 and 2023. The report reveals a worrying trend: actors in … Read more

Kaspersky antivirus banned in the United States

On June 20, 2024, the United States announced its decision to ban the use of Kaspersky antivirus software, a well-known Russian cybersecurity product. The ban applies to all Americans, both at home and abroad, due … Read more

Critical Vulnerabilities Found in Baxter Welch Allyn Products

On May 30, 2024, CISA publicized ICS Medical Alerts for Baxter products and medical devices. Baxter identified two critical vulnerabilities in its Welch Allyn products, namely the Welch Allyn Connex Spot Monitor and the Welch … Read more

A Misguided Cyber Operation: The French Mill Incident

A report recently published by Mandiant discloses that the Russian hackers group Sandworm mistakenly targeted a small mill in France, believing it was a hydroelectric dam. This erroneous attack was part of a broader campaign … Read more

Med-Data Settles Data Breach Legal Case Through $7 Million Agreement

Med-Data Inc., a revenue cycle management services provider based in Spring, TX, has reached a $7 million settlement to address all claims arising from a data breach spanning from 2018 to 2019, affecting around 136,000 … Read more

Green Ridge Behavioral Health Faces OCR HIPAA Action After Ransomware Attack

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), has announced the settlement of a ransomware investigation involving Green Ridge Behavioral Health, LLC, a Maryland-based psychiatric practice, highlighting the growing … Read more

BlackCat Ransomware Group Behind Change Healthcare Cyberattack

Change Healthcare, a leading provider of healthcare billing and data systems, finds itself grappling with a severe cybersecurity crisis following the detection of a malicious cyberattack on February 21, 2024. This attack, attributed to the … Read more

Cyberattack Exploiting ConnectWise Vulnerability Impacts Change Healthcare

The cyber attack exploiting a vulnerability in ConnectWise ScreenConnect software has led to significant disruptions at UnitedHealth’s Change Healthcare, impacting services across the United States. This incident has revealed critical vulnerabilities, affecting not just Change … Read more

Integris Health Reports 2.39 Million People Impacted by Cyberattack

Integris Health has finished the analysis of the files that were viewed/stolen as a result of a cyberattack in November 2023. It has submitted the breach report to the Department of Health and Human Services … Read more

$4.75 Million HIPAA Penalty on Montefiore Medical Center Due to Malicious Insider Incident

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) reported the first financial penalty issued in 2024 to settle alleged HIPAA violations. Montefiore Medical Center has consented to pay a $4.75 … Read more

Massive Data Breach Hits French Healthcare: Over 33 Million Affected

In what is being described as France’s largest ever cyberattack, the personal information of over 33 million individuals has been compromised. This breach targeted two French service providers, Viamedis and Almerys, responsible for processing healthcare … Read more

Data Breach Reports by Columbus Regional Healthcare System, Senior PsychCare, and Aria Care Partners

133K Record Data Breach at Columbus Regional Healthcare System Columbus Regional Healthcare System located in Whiteville, NC, has informed the Maine Attorney General about a patient data theft due to a cybersecurity incident. Unauthorized people … Read more

Microsoft targeted by Russian Intelligence Cyberattack

In January 2024, Microsoft disclosed a significant cybersecurity breach in its network, attributed to Nobelium, a group with alleged ties to Russia’s Foreign Intelligence Service. This incident highlights the evolving challenges in digital security that … Read more

Data Breach Reports by Electrostim Medical Services, Meridian Behavioral Healthcare and Network 180

543,000 Electrostim Medical Services Patients Affected by Data Breach The medical device firm Electrostim Medical Services, Inc. in Florida, which is also called EMSI, has reported that it encountered a cyberattack in May 2023 which … Read more

Data Breaches Reported by State of Maine, Affinity Legacy, The Charles Lea Center and Detroit Chassis

State of Maine Data Breach Impacts 450,000 Records The State of Maine has reported the theft of the protected health information (PHI) of 453,894 persons in the latest mass exploitation of a zero-day vulnerability in … Read more

1235 Next