Supply chain β›“ Supply Chain

RIBridges system Third-Party Breach (December 2024)

πŸ“… 2024-12-01 🏒 Deloitte
Primary Source β†—

Incident Details

Rhode Island confirms data breach after Brain Cipher ransomware attack. Rhode Island is warning that its RIBridges system, managed by Deloitte, suffered a data breach exposing residents’ personal information after the Brain Cipher ransomware gang hacked its systems. RIBridges is a modern integrated eligibility system (IES) used in Rhode Island to manage and deliver public assistance programs, helping streamline the administration of various social services. The incident was discovered on December 5, 2024, and following an evaluation by Deloitte, it is considered very likely that hackers stole files containing personally identifiable information and other data. Third-party company: Deloitte.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Deloitte
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-12-01 Breach occurred
  2. 2024-12-16 Publicly disclosed