Supply chain
⛓ Supply Chain
40 Healthcare Companies Third-Party Breach (December 2023)
Primary Source ↗Incident Details
10,000 people’s data stolen in genetic testing company Asper Biogene leak. Personal and health data belonging to approximately 10,000 people has been illegally downloaded from the Tartu-based genetic testing company Asper Biogene’s database, the State Prosecutor’s Office said on Thursday. Those affected are in the process of being notified. A criminal investigation has been launched by the Southern Prefectural Criminal Bureau which is in the process of collecting evidence. The Data Protection Inspectorate (Andmekaitse Inspektsioon) has also initiated a supervisory procedure against the data processor. Asper Biogene, which specializes in the diagnostics of hereditary diseases, alerted the Police, the State Information System Agency (Riigi Infosüsteemi Amet), and the Data Protection Inspectorate on November 11. Third-party company: Asper Biogene.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Asper Biogene
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2023-12-01 Breach occurred
- 2023-12-14 Publicly disclosed