Supply chain
⛓ Supply Chain
Serco Inc. Group Health Plan Third-Party Breach (August 2023)
Primary Source ↗Incident Details
August 2023 Healthcare Data Breach Report. There was a 21.4% month-over-month increase in healthcare data breaches in August. 68 data breaches of 500 or more records were reported to the HHS’ There was a 21.4% month-over-month increase in reported healthcare data breaches in August. Across the 68 reported data breaches, the protected health information of more than 11 million individuals was exposed or stolen. While there was a 34.3% month-over-month fall in the number of breached records, July’s total was exceptionally high. In August, almost 12 million records were reported as having been exposed or stolen, which is well above the 2023 average of 7.49 million records a month. Third-party company: Ipswitch, Inc..
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Ipswitch, Inc.
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2023-08-01 Breach occurred
- 2023-09-20 Publicly disclosed