Supply chain
β Supply Chain
Valley Health System Third-Party Breach (December 2023)
Primary Source βIncident Details
Healthcare software provider data breach impacts 2.7 million. ESO Solutions, a provider of software products for healthcare organizations and fire departments, disclosed that data belonging to 2.7 million patients has been compromised as a result of a ransomware attack. According to the notification, the intrusion occurred on September 28 and resulted in data being exfiltrated before the hackers encrypted a number of company systems. During the investigation of the incident, ESO Solutions discovered that the attackers accessed one machine that contained sensitive personal data. Third-party company: ESO Solutions, Inc..
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- ESO Solutions, Inc.
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2023-12-01 Breach occurred
- 2023-12-20 Publicly disclosed