Supply chain
⛓ Supply Chain
Blue Cross and Blue Shield of Massachusetts Third-Party Breach (June 2022)
Primary Source ↗Incident Details
BCBS of Massachusetts Reports Third-Party Vendor Data Breach | TechTarget. BCBS of Massachusetts reported a third-party vendor data breach involving its pension plan payment vendor. Blue Cross and Blue Shield (BCBS) of Massachusetts began notifying 4,855 individuals of a third-party vendor data breach, a notice on the Maine Attorney General’s Office website stated. The breach originated at LifeWorks US, a vendor used by BCBS of Massachusetts and BCBS of Massachusetts HMO Blue for services related to pension plan payments. Third-party company: LifeWorks US.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- LifeWorks US
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2022-06-01 Breach occurred
- 2022-07-25 Publicly disclosed