According to sources, the Missouri Department of Social Services (DSS) has disclosed a massive data breach involving confidential Medicaid healthcare information. The compromise was caused by the Clop ransomware group's data theft attack against IBM's MOVEit software. Since May 27, 2023, attackers have been targeting MOVEit Transfer servers using a zero-day vulnerability, CVE-2023-34362. This hack has affected over 600 organisations around the world, including corporations, educational institutions, and numerous government entities, and has profited Clop ransomware between $75 and $100 million from these attacks. The Missouri Department of Social Services made the details of the incident public on August 8, 2023, where they clarified that the leaked data is only about Medicaid services in the state. The breach is due to the compromise of IBM, the Department's external service provider, which uses MOVEit Transfer and was immediately disconnected from the Department's IT infrastructure in response to a security alert from Progress, the software provider. Additionally, in this attack no IBM systems were directly affected. Upon analysing the stolen data, the DSS has confirmed the presence of protected health information related to Missouri Medicaid participants, which includes information like names, department client numbers (DCNs), dates of birth, potential benefit eligibility, coverage details, and medical claims data. Further, the DSS said compromised files are complex and extensive, leading the Department to anticipate a gradual review process to fully assess the breach's scope. As a precaution, the Department is notifying all Missouri Medicaid participants enrolled in May 2023. In addition to this, individuals affected by the breach are advised to consider freezing their credit as a preventive measure against unauthorised account openings or fraudulent borrowing attempts. DSS also recommends that those impacted monitor their credit reports for unusual activity.
IBM released security patches for over 100 vulnerabilities across various products. The biggest sufferers of these patches were Storage Defender, for which patches were issued for ...
Fieldtex Products, a U.S.-based provider of contract sewing and medical supply fulfillment, has reported a data breach following an attack attributed to a well-known ransomware ope...
The Pierce County Library System (PCLS) has announced a major data breach affecting more than 340,000 individuals, including library patrons, employees, former employees, and some ...