Supply chain ⛓ Supply Chain

Blue Cross and Blue Shield of Massachusetts Third-Party Breach (June 2022)

📅 2022-06-01 🏢 LifeWorks US
Primary Source ↗

Incident Details

BCBS of Massachusetts Reports Third-Party Vendor Data Breach | TechTarget. BCBS of Massachusetts reported a third-party vendor data breach involving its pension plan payment vendor. Blue Cross and Blue Shield (BCBS) of Massachusetts began notifying 4,855 individuals of a third-party vendor data breach, a notice on the Maine Attorney General’s Office website stated. The breach originated at LifeWorks US, a vendor used by BCBS of Massachusetts and BCBS of Massachusetts HMO Blue for services related to pension plan payments. Third-party company: LifeWorks US.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
LifeWorks US
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2022-06-01 Breach occurred
  2. 2022-07-25 Publicly disclosed