Supply chain β›“ Supply Chain

Veterans Health Administration Third-Party Breach (December 2024)

πŸ“… 2024-12-01 🏒 DBP, Inc.
Primary Source β†—

Incident Details

Colonial Behavioral Health & Veterans Health Administration Patients Affected by Ransomware Attacks. Colonial Behavioral Health and a medical transcription service provider used by the Veterans Health Administration have experienced ransomware attacks Colonial Behavioral Health and a medical transcription service provider used by the Veterans Health Administration have experienced ransomware attacks that potentially involved the theft of patient data. Colonial Behavioral Health, a behavioral health and psychiatric service provider in the Greater Williamsburg Area of Virginia, has fallen victim to a ransomware attack. The attack was detected on or around October 4, 2024, when access to files and systems was disrupted. Immediate action was taken to contain the attack and prevent further unauthorized access to its systems and third-party cybersecurity experts were engaged to investigate the incident. Third-party company: DBP, Inc..

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
DBP, Inc.
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-12-01 Breach occurred
  2. 2024-12-03 Publicly disclosed