Supply chain ⛓ Supply Chain

Ramsey County, (Minnesota) Family Health Division Third-Party Breach (February 2021)

📅 2021-02-01 🏢 Netgain
Primary Source ↗

Incident Details

Netgain ransomware incident impacts local governments. The ransomware incident that Netgain, a provider of managed IT services, had late last year rippled onto its customers. Now, Ramsey County, Minnesota, is informing clients of the Family Health Division program that the hackers may have accessed personal data. The government of Ramsey County learned about the potential breach on December 2, 2020, when Netagin let them know of the attack and the impact it could have. “Netgain determined that the ransomware incident affected data within an application used by Ramsey County’s Family Health Division to document home visits” - Ramsey County Government. Third-party company: Netgain.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Netgain
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2021-02-01 Breach occurred
  2. 2021-02-02 Publicly disclosed