Attackers used social engineering to access third-party business apps and steal patient information


Heart monitoring biz iRhythm says thieves made off with patient health information and tried to turn it into a payday.

The California-based cardiac monitoring specialist offers customers a wearable device that collects data, then analyzes it to create reports about heart health. The company said it detected unauthorized activity on June 8 and launched an investigation with the help of third-party cybersecurity experts. A day later, the company received messages from a cybercriminal claiming to have obtained sensitive information, including proprietary company data, protected health information, and other personal information.

Read more…
Source:  


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • UK: 767 sex crime victims affected by Norfolk police data leak

    December 27, 2023

    Hundreds of victims of sexual offences were among those to have personal details leaked as part of a huge police data breach. Norfolk and Suffolk constabularies revealed in August that a technical issue had led to sensitive raw data about crimes being mistakenly disclosed as part of responses to freedom of information requests. Among the data ...

  • Michigan health system reports 2nd data breach, affecting more than 1M patients

    December 27, 2023

    A health system in Michigan has experienced its second cybersecurity breach this year, affecting more than 1 million patients, according to state officials. Michigan Attorney General Dana Nessel announced Tuesday there was a breach at HealthEC, a vendor that provides services to Corewell Health’s southeast Michigan properties. The breach exposed patients’ personal and medical information Read more… Source: ...

  • Motorists data stolen as RingGo parking app-owner hit by cyber attack

    December 26, 2023

    Hackers have stolen data including partial credit card numbers from parking apps used by millions of motorists. EasyPark, which owns RingGo and ParkMobile, said the details of at least 950 customers in the UK had been stolen by hackers, including names, phone numbers, addresses, email addresses and parts of credit card numbers. Read more… Source: MSN News  

  • CBS, Paramount owner National Amusements says it was hacked

    December 26, 2023

    National Amusements, the cinema chain and corporate parent giant of media giants Paramount and CBS, has confirmed it experienced a data breach in which hackers stole the personal information of tens of thousands of people. The private media conglomerate said in a legally required filing with Maine’s attorney general that hackers stole personal information on 82,128 ...

  • Estonia: At least one case of extortion reported following Asper Biogene data leak

    December 25, 2023

    Investigations into the Asper Biogene data leak that came to light last week are ongoing, and there is already at least one known case of an attempt to extort money from an individual in connection with the data leak. When the data theft case came to light, police warned that the situation could be exploited by ...

  • Ubisoft apparently stopped a 900GB data breach

    December 24, 2023

    Just days after Insomniac suffered a horrible data breach, Ubisoft may have avoided the same fate. Security collective VX-Underground shared a report on X that, on Dec. 20, an “unknown Threat Actor” got access to Ubisoft’s internal tools, sharing screenshots online. They allegedly intended to get 900GB worth of data from the French game publisher behind ...