Supply chain β›“ Supply Chain

Blue Cross and Blue Shield of Minnesota and Blue Plus Third-Party Breach (November 2023)

πŸ“… 2023-11-01 🏒 Welltok
Primary Source β†—

Incident Details

Welltok data breach exposes data of 8.5 million US patients. Healthcare SaaS provider Welltok is warning that a data breach exposed the personal data of nearly 8.5 million patients in the U.S. after a file transfer program used by the company was hacked in a data theft attack. Welltok works with health service providers across the U.S., maintaining online wellness programs, holding databases with personal patient data, generating predictive analytics, and supporting healthcare needs like medication adherence and pandemic response. Earlier this year, the Clop ransomware gang exploited a zero-day vulnerability in the MOVEit software to breach thousands of organizations worldwide, following up with extortion demands and data leaks impacting over 77 million people. Third-party company: Welltok.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Welltok
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2023-11-01 Breach occurred
  2. 2023-11-22 Publicly disclosed