Ransomware

HIPAA Journal

πŸ“… 2024-11-01 🏒 ARC Community Services administrative systems
Primary Source β†—

Incident Details

ARC Community Services, a Wisconsin-based nonprofit providing community living and support services for people with intellectual and developmental disabilities, announced a November 2024 ransomware attack in early 2025. The attack compromised personal information of clients and employees including names, Social Security numbers, dates of birth, financial account information, and health/treatment information. The incident highlights the vulnerability of smaller human services nonprofits that handle sensitive medical and personal data but often lack robust cybersecurity resources.

Technical Details

Initial Attack Vector
CWE-284: Improper Access Control
Vendor / Product
ARC Community Services administrative systems

Timeline

  1. 2024-11-01 Breach occurred
  2. 2025-01-01 Publicly disclosed
  3. 2025-01-01 Customers notified