{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-magellan-health-ransomware-began-with-a-phishing-email-impersonating-a-c"},"incident":{"slug":"2020-magellan-health-ransomware-began-with-a-phishing-email-impersonating-a-c","title":"Magellan Health ransomware began with a phishing email impersonating a client","date":"2020-04-06","date_precision":"day","year":2020,"victim_org":"Magellan Health","sector":"Healthcare","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Vendor / Supply Chain Impersonation","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Data Breach","Credential Theft","Extortion"],"loss_usd":1430000,"loss_kind":"business_impact","loss_note":"US$1.43 million class-action settlement resolving claims over the breach and the delay in notification.","records_affected":364892,"threat_actor":null,"summary":"Magellan Health, a US managed care and behavioral health company, was hit by ransomware on 11 April 2020. The investigation traced the intrusion to 6 April, when an employee responded to a spear-phishing email in which the attacker impersonated a Magellan client. Before encrypting files the attackers stole employee data and deployed credential-harvesting malware. At least 364,892 individuals across Magellan subsidiaries and partner organisations were affected.","how_it_worked":"The attacker impersonated one of Magellan's own clients, which is a stronger pretext than a generic executive spoof because a managed care company's staff correspond with client organisations constantly and are expected to be responsive to them. The employee provided access credentials in response to that message. Over the following five days the attackers moved through the network, reached a corporate server holding employee records including tax documentation with Social Security numbers, exfiltrated a subset of it, and installed software to harvest further log-ins before triggering encryption. The five-day dwell time is where the data theft happened.","lessons":"Client-impersonation phishing defeats seniority-based suspicion, so the control is MFA plus detection of internal reconnaissance in the days between the click and the encryption.","confidence":"Confirmed","sources":[{"title":"Data Stolen in Magellan Health Ransomware Attack","url":"https://www.hipaajournal.com/magellan-health-suffers-ransomware-attack/","publisher":"HIPAA Journal"},{"title":"Healthcare giant Magellan Health hit by ransomware attack","url":"https://www.bleepingcomputer.com/news/security/healthcare-giant-magellan-health-hit-by-ransomware-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-magellan-health-ransomware-began-with-a-phishing-email-impersonating-a-c"}}