Supply chain ⛓ Supply Chain

Medical Facilities Third-Party Breach (Deecember 2020)

📅 2020-01-01 🏢 iSofH
Primary Source ↗

Incident Details

Leaky Server Exposes 12 Million Healthcare Records to Meow Attacker. Extortion and fraud risks persist for tens of thousands of patients. A healthcare technology company leaked 12 million records on patients including highly sensitive diagnoses, before the exposed cloud server was struck by the infamous “meow” attacker, researchers have revealed. A team at SafetyDetectives led by Anurag Sen discovered the leaky Elasticsearch server in late October after a routine IP address scan, although it’s unknown how long the data was exposed for before that. Third-party company: iSofH.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
iSofH
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2020-01-01 Breach occurred
  2. 2020-12-23 Publicly disclosed