Supply chain
β Supply Chain
Blue Cross and Blue Shield of Minnesota and Blue Plus Third-Party Breach (November 2023)
Primary Source βIncident Details
Welltok data breach exposes data of 8.5 million US patients. Healthcare SaaS provider Welltok is warning that a data breach exposed the personal data of nearly 8.5 million patients in the U.S. after a file transfer program used by the company was hacked in a data theft attack. Welltok works with health service providers across the U.S., maintaining online wellness programs, holding databases with personal patient data, generating predictive analytics, and supporting healthcare needs like medication adherence and pandemic response. Earlier this year, the Clop ransomware gang exploited a zero-day vulnerability in the MOVEit software to breach thousands of organizations worldwide, following up with extortion demands and data leaks impacting over 77 million people. Third-party company: Welltok.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Welltok
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2023-11-01 Breach occurred
- 2023-11-22 Publicly disclosed