Supply chain
β Supply Chain
RIBridges system Third-Party Breach (December 2024)
Primary Source βIncident Details
Rhode Island confirms data breach after Brain Cipher ransomware attack. Rhode Island is warning that its RIBridges system, managed by Deloitte, suffered a data breach exposing residents’ personal information after the Brain Cipher ransomware gang hacked its systems. RIBridges is a modern integrated eligibility system (IES) used in Rhode Island to manage and deliver public assistance programs, helping streamline the administration of various social services. The incident was discovered on December 5, 2024, and following an evaluation by Deloitte, it is considered very likely that hackers stole files containing personally identifiable information and other data. Third-party company: Deloitte.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Deloitte
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2024-12-01 Breach occurred
- 2024-12-16 Publicly disclosed