UnitedHealth data breach caused by lack of multifactor authentification


Hackers breached the computer system of a UnitedHealth Group subsidiary and released ransomware after stealing someone’s password, CEO Andrew Witty testified Wednesday on Capitol Hill.

The cybercriminals entered through a portal that didn’t have multifactor authentification (MFA) enabled. During an hourslong congressional hearing, Witty told lawmakers that the company has not yet determined how many patients and health care professionals were impacted by the cyberattack on Change Healthcare in February.

Read more…
Source: MSN News


Sign up for our Newsletter


Related:

  • Internet-Connected Medical Washer-Disinfector Found Vulnerable to Hacking

    March 27, 2017

    Internet-of-Things devices are turning every industry into the computer industry, making customers think that their lives would be much easier with smart devices. There are, of course, some really good reasons to connect certain devices to the Internet. For example, remotely switching on your A/C a few minutes before you enter your home, instead of leaving ...

  • 76 iOS Apps, Including Medical and Banking Tools, Are Exposing Data to Hackers

    February 7, 2017

    Seventy-six popular apps in the Apple App Store are vulnerable to silent interception of TLS-protected data due to a poor implementation of the cryptographic protocol. According to researcher Will Strafach, who wrote on Medium, the apps are vulnerable to man-in-the-middle attacks. Data that is normally protected by Transport Layer Security can now be read or manipulated ...

  • Google mistakes the entire NHS for massive cyber-attacking botnet

    February 1, 2017

    Google is blocking access to the entire NHS network, mistaking the amount of traffic it is currently receiving as a cyber attack. An email from an NHS trust’s IT department seen by The Register confirmed that the US search giant has mistaken the current traffic levels for a botnet. The email headed “Google Access” stated: “Google is ...