Supply chain
β Supply Chain
A (probably) Mexican government healt agency Third-Party Breach (August 2018)
Primary Source βIncident Details
Telemedicine vendor breaches the data of 2.4 million patients in Mexico. A configuration error left a database filled with healthcare data exposed on the internet, and the data could be accessed and changed by anyone without a password. The personal data of 2,373,764 patients was left exposed online after Hova Health, a telemedicine company based in Mexico, misconfigured a MongoDB database. Security researcher Bob Diachecko made the discovery using the Shodan.io search engine, which scans the internet for open ports on connected devices and web servers. The database was publically available and could be accessed or changed by anyone, even without a password. Third-party company: Hova Health.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Hova Health
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2018-08-01 Breach occurred
- 2018-08-01 Publicly disclosed