Supply chain
β Supply Chain
Arietis Health Third-Party Breach (October 2023)
Primary Source βIncident Details
RCM Company Reports Data Breach Tied to MOVEit Software, 1.9M Impacted | TechTarget. The revenue cycle management company reported a data breach that impacted more than 1.9 million individuals across more than 50 healthcare organizations. Revenue cycle management company Arietis Health notified more than 1.9 million individuals of a data breach stemming from the MOVEit Transfer hack. As previously reported , entities across all sectors have felt the effects of the hack, which impacted commonly used file transfer software. MOVEit disclosed the vulnerability on May 31 and issued a patch on the same day. Third-party company: Ipswitch, Inc..
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Ipswitch, Inc.
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2023-10-01 Breach occurred
- 2023-10-17 Publicly disclosed