Supply chain
⛓ Supply Chain
Medical Facilities Third-Party Breach (Deecember 2020)
Primary Source ↗Incident Details
Leaky Server Exposes 12 Million Healthcare Records to Meow Attacker. Extortion and fraud risks persist for tens of thousands of patients. A healthcare technology company leaked 12 million records on patients including highly sensitive diagnoses, before the exposed cloud server was struck by the infamous “meow” attacker, researchers have revealed. A team at SafetyDetectives led by Anurag Sen discovered the leaky Elasticsearch server in late October after a routine IP address scan, although it’s unknown how long the data was exposed for before that. Third-party company: iSofH.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- iSofH
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2020-01-01 Breach occurred
- 2020-12-23 Publicly disclosed