{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-phishing-email-compromises-53-la-county-public-health-staff-accounts-200"},"incident":{"slug":"2024-phishing-email-compromises-53-la-county-public-health-staff-accounts-200","title":"Phishing email compromises 53 LA County Public Health staff accounts, 200,000 affected","date":"2024-02-19","date_precision":"day","year":2024,"victim_org":"Los Angeles County Department of Public Health","sector":"Government","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":200000,"threat_actor":null,"summary":"The Los Angeles County Department of Public Health disclosed that between 19 and 20 February 2024 a phishing email compromised the log-in credentials of 53 employees, exposing the personal and health information of more than 200,000 individuals. Exposed data included names, dates of birth, Social Security numbers, diagnoses, prescriptions, health insurance and Medicare or Medi-Cal details. The same phishing campaign also hit LA County's Department of Health Services and Department of Mental Health.","how_it_worked":"A phishing email circulated through the department and 53 separate employees entered their credentials on the attacker's page within roughly 24 hours, which shows the message was well matched to the environment rather than obviously fraudulent. With valid log-ins the attacker read the contents of those mailboxes, which in a county public health agency contain case correspondence carrying patient names, diagnoses, prescriptions and benefit identifiers. The department responded by disabling accounts, resetting devices, blocking the phishing sites and quarantining the messages, but by then two days of mailbox access across dozens of accounts had already occurred.","lessons":"Phishing-resistant MFA across county staff accounts would have made the harvested passwords useless, and rapid cross-department alerting would have cut the exposure window.","confidence":"Confirmed","sources":[{"title":"200,000 Impacted by Data Breach at Los Angeles County Public Health Agency","url":"https://www.securityweek.com/200000-impacted-by-data-breach-at-los-angeles-county-public-health-agency/","publisher":"SecurityWeek"},{"title":"Los Angeles Public Health Department Discloses Large Data Breach","url":"https://www.infosecurity-magazine.com/news/los-angeles-health-data-breach/","publisher":"Infosecurity Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-phishing-email-compromises-53-la-county-public-health-staff-accounts-200"}}