{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-unitypoint-health-phishing-of-executive-spoofed-emails-exposes-1-4-milli"},"incident":{"slug":"2018-unitypoint-health-phishing-of-executive-spoofed-emails-exposes-1-4-milli","title":"UnityPoint Health phishing of executive-spoofed emails exposes 1.4 million patients","date":"2018-03","date_precision":"month","year":2018,"victim_org":"UnityPoint Health","sector":"Healthcare","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":2800000,"loss_kind":"business_impact","loss_note":"US$2.8 million class-action settlement to resolve litigation over the breach.","records_affected":1400000,"threat_actor":null,"summary":"UnityPoint Health, an Iowa-based health system, disclosed in July 2018 that a phishing campaign had compromised multiple employee email accounts between 14 March and 3 April 2018, exposing data on approximately 1.4 million patients. It was the largest US health data breach reported that year. Investigators concluded the attackers were most likely trying to divert vendor or payroll payments rather than steal medical records.","how_it_worked":"The phishing emails were crafted to appear to come from an executive inside UnityPoint Health, which gave them the internal legitimacy that gets messages read and links clicked. Staff who followed the links and entered their credentials handed over access to their mailboxes, and the attackers used those accounts for about three weeks. The financial motive shows in what they did next: they hunted for vendor invoices and payroll processes to redirect. The patient data exposure, which included medical, insurance, Social Security and in some cases payment card details, was collateral, simply whatever happened to be sitting in the compromised inboxes.","lessons":"Multi-factor authentication on clinical staff email, and a policy against storing patient identifiers in mailboxes, would have limited both the access and the exposure.","confidence":"Confirmed","sources":[{"title":"1.4 million patient records breached in UnityPoint Health phishing attack","url":"https://www.healthcareitnews.com/news/14-million-patient-records-breached-unitypoint-health-phishing-attack","publisher":"Healthcare IT News"},{"title":"1.4 Million Patients Warned About UnityPoint Health Phishing Attack","url":"https://www.hipaajournal.com/unitypoint-health-phishing-attack-1-4-million-patients/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-unitypoint-health-phishing-of-executive-spoofed-emails-exposes-1-4-milli"}}