Supply chain
β Supply Chain
Veterans Health Administration Third-Party Breach (December 2024)
Primary Source βIncident Details
Colonial Behavioral Health & Veterans Health Administration Patients Affected by Ransomware Attacks. Colonial Behavioral Health and a medical transcription service provider used by the Veterans Health Administration have experienced ransomware attacks Colonial Behavioral Health and a medical transcription service provider used by the Veterans Health Administration have experienced ransomware attacks that potentially involved the theft of patient data. Colonial Behavioral Health, a behavioral health and psychiatric service provider in the Greater Williamsburg Area of Virginia, has fallen victim to a ransomware attack. The attack was detected on or around October 4, 2024, when access to files and systems was disrupted. Immediate action was taken to contain the attack and prevent further unauthorized access to its systems and third-party cybersecurity experts were engaged to investigate the incident. Third-party company: DBP, Inc..
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- DBP, Inc.
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2024-12-01 Breach occurred
- 2024-12-03 Publicly disclosed