Supply chain ⛓ Supply Chain

Community Care Physicians Third-Party Breach (February 2020)

📅 2020-02-01 🏢 BST
Primary Source ↗

Incident Details

Accounting Firm Ransomware Hack Affects Community Care Patient Data | TechTarget. This week's breach roundup is led by a ransomware attack on the accounting firm BST, which potentially compromised patient data from Community Care Physicians; Maze ransomware is suspected. New York-based accounting firm BST was recently infected with Maze malware, which potentially compromised patient data from Community Care Physicians. According to the notification , BST fell victim to a ransomware attack in December. The impacted network contained data from the accounting firm’s local clients, to which BST provides accounting and tax services. CCP data was included in those records. But its systems were not impacted by the event. Third-party company: BST.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
BST
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2020-02-01 Breach occurred
  2. 2020-02-26 Publicly disclosed