Supply chain β›“ Supply Chain

Rady Children Hospital, Sonoma Valley Hospital, Innova Health, OSF Third-Party Breach (October 2020)

πŸ“… 2020-10-01 🏒 BlackBaud
Primary Source β†—

Incident Details

1M Inova Health Individuals Added to Blackbaud Breach Victim Tally | TechTarget. This week's breach roundup is led by the Blackbuad ransomware attack, which added more than 2 million affected individuals and patients in the weeks following its initial notice, such as 1M from Inova. The Blackbaud breach victim tally has climbed to nearly 3 million healthcare-connected entities and other nonprofits. In the last week, Inova Health System reported more than 1 million individuals were affected by the incident, as well as several other healthcare provider organizations. Blackbaud, a cloud computing vendor for a range of nonprofits, foundations, corporations, education institutions, healthcare entities, and change agents, reported that its self-hosted environment was hit with a ransomware attack on May 14. Third-party company: BlackBaud.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
BlackBaud
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2020-10-01 Breach occurred
  2. 2020-09-14 Publicly disclosed