{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:15:34.087Z","total":15,"returned":15,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-abbott-investigates-shinyhunters-claim-after-mid-june-vishing-on-employe","title":"Abbott investigates ShinyHunters claim after mid-June vishing on employees","date":"2026-06","date_precision":"month","year":2026,"victim_org":"Abbott Laboratories (legacy Exact Sciences systems)","sector":"Healthcare","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"ShinyHunters conducted vishing attacks against Abbott Laboratories employees in mid-June 2026 and compromised a Microsoft Entra single sign-on account that opened certain internal systems, according to reporting on the company's investigation. The group claimed 30 million rows of customer data including names, contact details, dates of birth and one million Social Security numbers, with a publication deadline of 21 July 2026. The affected systems were legacy Exact Sciences infrastructure acquired by Abbott in late 2025.","how_it_worked":"Callers impersonating internal IT reached Abbott staff and steered them into an Entra sign-in they did not control, capturing the credential and the multi-factor response in the same call. The single compromised SSO identity federated into internal systems inherited from the Exact Sciences acquisition, an environment less likely to have been fully folded into Abbott's identity and monitoring controls. A separate actor using the handle ShadowByt3$ claimed access to Abbott's LabCentral portal on 4 July using compromised customer credentials; Abbott said that portal holds only non-sensitive technical documents.","lessons":"Acquired estates need identity consolidation onto phishing-resistant MFA before the integration backlog is worked through, since attackers target exactly the tenant that has not been migrated yet.","confidence":"Reported","sources":[{"title":"Abbott Investigating Cyberattack Claims From Two Threat Actors","url":"https://www.hipaajournal.com/abbott-investigating-cyberattack-claims/","publisher":"HIPAA Journal"},{"title":"Abbott investigates after ShinyHunters claims massive data theft","url":"https://www.paubox.com/blog/abbott-investigates-after-shinyhunters-claims-massive-data-theft","publisher":"Paubox"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-abbott-investigates-shinyhunters-claim-after-mid-june-vishing-on-employe"},{"title":"Quantum Health network breached after social engineering call to a user","date":"2026-05-29","date_precision":"day","victim_org":"Quantum Health","sector":"Healthcare","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"No confirmation that synthetic voice was used on the call.","outcomes":["Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No loss figure disclosed.","records_affected":null,"threat_actor":null,"summary":"A threat actor telephoned a Quantum Health user on May 29, 2026 and used social engineering to obtain network access credentials. The unauthorised party retained access from May 29 through June 1, 2026, when a network disruption led to discovery. Exposed data included names, addresses, dates of birth, Social Security numbers, diagnosis and treatment information, prescriptions, provider names, insurance details and claims information. The number of affected individuals had not been disclosed.","how_it_worked":"The intrusion started with a phone call rather than an email or an exploit. The caller persuaded a legitimate user to hand over the credentials needed to reach the network, and the attacker then held that access for roughly four days. Because the login was valid and used in a normal way, nothing surfaced until a network disruption on June 1 prompted investigation. HIPAA Journal noted that the tradecraft aligns with tactics commonly employed by the ShinyHunters threat group, though no ransomware operation claimed the incident.","lessons":"Phishing-resistant MFA prevents a disclosed password from being usable, and impossible-travel or new-device alerts would have flagged the four-day window of unfamiliar access.","confidence":"Reported","sources":[{"title":"Vishing Attack on Quantum Health Network Exposed Patient Data","url":"https://www.hipaajournal.com/quantum-health-precision-imaging-centers-heart-america-data-breaches/","publisher":"The HIPAA Journal"}],"entry_type":"incident","slug":"2026-quantum-health-network-breached-after-social-engineering-call-to-a-user","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-quantum-health-network-breached-after-social-engineering-call-to-a-user"},{"slug":"2026-hims-hers-support-tickets-stolen-through-compromised-okta-sso-accounts","title":"Hims & Hers support tickets stolen through compromised Okta SSO accounts","date":"2026-02-04","date_precision":"day","year":2026,"victim_org":"Hims & Hers Health","sector":"Healthcare","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Telehealth company Hims & Hers disclosed that attackers reached its Zendesk support platform between 4 and 7 February 2026 by compromising Okta single sign-on accounts. Suspicious activity was spotted on 5 February and the breach confirmed on 3 March. Millions of customer support tickets containing names, contact details and request content were taken. The company said medical records and clinician communications were not involved. ShinyHunters conducted the breach.","how_it_worked":"Access came through Okta SSO accounts compromised as part of the ShinyHunters campaign that pairs IT-impersonation phone calls with real-time adversary-in-the-middle login pages, capturing both password and MFA response. Because Zendesk was federated behind Okta, a single stolen identity opened the support desk, where free-text tickets from a telehealth service carry more sensitive detail than the structured customer record does. The attackers exported tickets in bulk and moved to extortion. Hims & Hers is offering 12 months of credit monitoring.","lessons":"Support platforms federated behind SSO inherit the identity provider's weakest authentication; phishing-resistant MFA plus export-volume alerting on the ticketing system is the pair that catches this.","confidence":"Confirmed","sources":[{"title":"Hims & Hers warns of data breach after Zendesk support ticket breach","url":"https://www.bleepingcomputer.com/news/security/hims-and-hers-warns-of-data-breach-after-zendesk-support-ticket-breach/","publisher":"BleepingComputer"},{"title":"Telehealth Giant Hims & Hers Announces Data Breach","url":"https://www.hipaajournal.com/him-hers-data-breach/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-hims-hers-support-tickets-stolen-through-compromised-okta-sso-accounts"},{"slug":"2026-phishing-attack-on-healthcare-ai-firm-xsolis-exposes-1-4-million-patient","title":"Phishing attack on healthcare AI firm Xsolis exposes 1.4 million patients","date":"2026-01-20","date_precision":"day","year":2026,"victim_org":"Xsolis","sector":"Healthcare","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":1396519,"threat_actor":null,"summary":"Nashville-based healthcare AI company Xsolis, whose utilisation-management platform is used by payers and health systems, suffered a targeted phishing attack on 20 January 2026 and detected the unauthorised activity two days later. Files containing names, addresses, dates of birth, Social Security numbers, health insurance details and treatment information were taken. 1,396,519 individuals were reported affected to HHS. No group claimed responsibility.","how_it_worked":"Xsolis described the entry point as a targeted phishing attack against its own staff rather than an exploited vulnerability. The attacker reached an employee mailbox or account and, over roughly a two-day window before detection on 22 January, accessed and copied files holding protected health information belonging to patients of Xsolis's health system and payer customers. The company has not published the pretext used, the sender identity spoofed, or whether MFA was bypassed.","lessons":"Phishing-resistant MFA on email and any admin console, plus data-loss monitoring on bulk file access to PHI repositories, is what converts a successful lure into a contained account compromise.","confidence":"Confirmed","sources":[{"title":"Phishing attack on healthcare firm Xsolis impacts 1.4 million people","url":"https://www.helpnetsecurity.com/2026/06/24/xsolis-data-breach-phishing-attack/","publisher":"Help Net Security"},{"title":"Xsolis Data Breach Affects 1.4M Individuals","url":"https://www.hipaajournal.com/xsolis-data-breach/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-phishing-attack-on-healthcare-ai-firm-xsolis-exposes-1-4-million-patient"},{"title":"Interlock ransomware uses ClickFix fake CAPTCHA prompts for initial access","date":"2025-07-22","date_precision":"day","victim_org":"Multiple businesses and critical infrastructure organisations (campaign)","sector":"Healthcare","country":"Multiple","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported in the advisory.","outcomes":["Ransomware Deployment","Extortion","Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No aggregate loss figure published; the advisory notes Interlock does not state an initial ransom amount in its notes.","records_affected":null,"threat_actor":"Interlock ransomware group","summary":"A joint advisory from CISA, the FBI, HHS and MS-ISAC published on 22 July 2025 describes the Interlock ransomware group, active since late September 2024 against businesses and critical infrastructure in North America and Europe with notable impact on healthcare. The advisory documents two deception-based initial access routes: drive-by downloads from compromised legitimate websites, and the ClickFix technique in which victims are tricked into running a malicious payload by clicking a fake CAPTCHA prompt.","how_it_worked":"Visitors to compromised but otherwise legitimate websites were served a page claiming they needed to prove they were human or fix a display problem. The page silently copied a command to the clipboard and instructed the user to open the Windows Run dialog, paste and press Enter, which executed PowerShell that fetched a remote access trojan. Because the victim types the command themselves, no download prompt or macro warning appears and email gateways are entirely bypassed. Interlock operators then used the foothold for credential theft with infostealers and keyloggers, lateral movement over RDP, data exfiltration to cloud storage, and double-extortion encryption of Windows and Linux systems.","lessons":"Instrument and alert on PowerShell or mshta launched from explorer.exe via the Run dialog, and block clipboard-to-shell execution paths through application control; no legitimate CAPTCHA ever asks a user to run a command.","confidence":"Confirmed","sources":[{"title":"#StopRansomware: Interlock (AA25-203A)","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-203a","publisher":"CISA / FBI / HHS / MS-ISAC"},{"title":"#StopRansomware: Interlock (PDF)","url":"https://www.ic3.gov/CSA/2025/250722.pdf","publisher":"FBI Internet Crime Complaint Center"},{"title":"Feds Issue Interlock Ransomware Warning as Healthcare Attacks Spike","url":"https://www.hipaajournal.com/interlock-ransomware-alert-2025/","publisher":"HIPAA Journal"}],"entry_type":"campaign","slug":"2025-interlock-ransomware-uses-clickfix-fake-captcha-prompts-for-initial-acce","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-interlock-ransomware-uses-clickfix-fake-captcha-prompts-for-initial-acce"},{"slug":"2025-arizona-arthritis-and-rheumatology-associates-phishing-breach-hits-5-509","title":"Arizona Arthritis and Rheumatology Associates phishing breach hits 5,509 patients","date":"2025-03-03","date_precision":"day","year":2025,"victim_org":"Arizona Arthritis and Rheumatology Associates","sector":"Healthcare","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5509,"threat_actor":null,"summary":"Arizona Arthritis and Rheumatology Associates detected unauthorised access to employee Microsoft 365 email accounts on 3 March 2025 after a successful phishing attack. The compromised mailboxes contained patient names, provider and clinic names, dates of birth, sex, insurance company names, balances, appointment dates and limited health information and identification numbers for 5,509 individuals. The practice said it detected the intrusion within hours and offered affected patients identity monitoring.","how_it_worked":"Staff received phishing email designed to look like routine Microsoft 365 account or document notifications and entered their work credentials on an attacker-controlled sign-in page. The trust signals abused were the familiar Microsoft branding and the ordinary rhythm of clinic email, where staff process insurance, referral and scheduling messages all day and open unfamiliar attachments as a matter of course. With valid credentials the attacker signed into the mailboxes and had immediate access to months of patient correspondence. Because the access used legitimate credentials from a normal cloud client, nothing looked malicious until sign-in anomalies were reviewed.","lessons":"Phishing-resistant MFA on clinical email accounts, plus conditional access blocking unfamiliar sign-in locations, would have made the harvested passwords useless.","confidence":"Confirmed","sources":[{"title":"Arizona Arthritis and Rheumatology Associates & Mon Health Report Phishing Incidents","url":"https://www.hipaajournal.com/arizona-arthritis-rheumatology-associates-mon-health-phishing-attacks/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-arizona-arthritis-and-rheumatology-associates-phishing-breach-hits-5-509"},{"slug":"2025-monongalia-health-system-email-phishing-breach-affects-4-895-patients","title":"Monongalia Health System email phishing breach affects 4,895 patients","date":"2025-03-03","date_precision":"day","year":2025,"victim_org":"Monongalia Health System (Mon Health)","sector":"Healthcare","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":4895,"threat_actor":null,"summary":"West Virginia's Monongalia Health System detected unauthorised access to employee email accounts on 3 March 2025 following a phishing attack. The affected mailboxes held names, physician names, facility names and limited medical information for 4,895 individuals, and for a smaller subset Social Security numbers and health insurance policy numbers. Mon Health offered complimentary identity monitoring, retrained staff and strengthened its anti-phishing controls.","how_it_worked":"Employees were sent phishing messages that imitated routine internal or Microsoft 365 notifications and were induced to enter their work credentials on a lookalike sign-in page. Hospital email is a high-yield target because clinical and billing staff exchange large volumes of patient-identifying correspondence with outside parties, so an unexpected message about a shared document or account issue does not stand out. With the harvested credentials the attacker signed in as the employee and had access to the full mailbox history. The activity resembled normal user logins, which is why detection depended on account anomaly review rather than malware alerts.","lessons":"Enforcing phishing-resistant MFA and automatically expiring or archiving mailbox contents containing PHI would have both blocked the login and limited what a single compromised account exposed.","confidence":"Confirmed","sources":[{"title":"Arizona Arthritis and Rheumatology Associates & Mon Health Report Phishing Incidents","url":"https://www.hipaajournal.com/arizona-arthritis-rheumatology-associates-mon-health-phishing-attacks/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-monongalia-health-system-email-phishing-breach-affects-4-895-patients"},{"slug":"2024-michigan-medicine-employee-approved-an-unsolicited-mfa-prompt-exposing-5","title":"Michigan Medicine employee approved an unsolicited MFA prompt, exposing 57,891 patients","date":"2024-07-30","date_precision":"day","year":2024,"victim_org":"Michigan Medicine (University of Michigan)","sector":"Healthcare","country":"United States","primary_vector":"MFA Fatigue / Push Bombing","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":57891,"threat_actor":null,"summary":"Michigan Medicine notified approximately 57,891 individuals that an employee email account was compromised on 30 July 2024 after the employee accepted an unsolicited multi-factor authentication prompt. Exposed information included names, medical record numbers, addresses, dates of birth and diagnostic and treatment details. This followed a separate May 2024 incident in which three employee email accounts were compromised, affecting about 56,953 people.","how_it_worked":"The attacker already held the employee's password and needed only the second factor, so they triggered an authentication push to the employee's device. The employee approved it. That is the whole attack: no link was clicked and no page was visited, only a notification approved out of reflex or annoyance, which is why push-based MFA fails in a way that hardware keys cannot. With the account open, the attacker had ordinary access to a clinician's mailbox, where routine correspondence carries medical record numbers, diagnoses and treatment details for tens of thousands of patients. Michigan Medicine disabled the account, blocked the attacker's IP address and forced password resets.","lessons":"Number matching or, better, phishing-resistant hardware authenticators remove the ability to grant access by approving a prompt, and staff need a clear instruction to report unexpected prompts.","confidence":"Confirmed","sources":[{"title":"Michigan Medicine notifies patients of health information breach","url":"https://www.michiganmedicine.org/news-release/michigan-medicine-notifies-patients-health-information-breach-3","publisher":"Michigan Medicine"},{"title":"Michigan Medicine email breach exposes patient information","url":"https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/michigan-medicine-email-breach-exposes-patient-information/","publisher":"Becker's Hospital Review"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-michigan-medicine-employee-approved-an-unsolicited-mfa-prompt-exposing-5"},{"slug":"2024-ascension-ransomware-attack-began-when-an-employee-downloaded-a-maliciou","title":"Ascension ransomware attack began when an employee downloaded a malicious file","date":"2024-05-08","date_precision":"day","year":2024,"victim_org":"Ascension","sector":"Healthcare","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Watering Hole / Malvertising"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Data Breach","Service Disruption"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5600000,"threat_actor":"Black Basta (reported)","summary":"Ascension, one of the largest US non-profit health systems, was hit by ransomware detected on 8 May 2024, disrupting electronic health records, diverting ambulances and forcing clinicians onto paper across 140 hospitals. Ascension said an employee had downloaded a malicious file onto a company device, believing it to be legitimate, and described it as an honest mistake. Attackers accessed files on seven of about 25,000 servers. Ascension ultimately notified approximately 5.6 million individuals.","how_it_worked":"A staff member downloaded a file to a work computer in the belief that it was legitimate, which is the form of compromise that has largely replaced the classic attachment: the user is looking for something, a document, an update, a utility, and takes delivery of malware from what appears to be an ordinary source. That single endpoint gave the operators their foothold in a health system spanning 140 hospitals, where the pressure to keep clinical systems continuously available works against aggressive segmentation. The attackers reached and exfiltrated data from seven servers before deploying encryption, forcing weeks of downtime procedures across the network.","lessons":"Application allowlisting and blocking user-initiated downloads of executables on clinical endpoints, combined with segmentation, are what keep one mistaken download from stopping 140 hospitals.","confidence":"Confirmed","sources":[{"title":"Ascension hacked after employee downloaded malicious file","url":"https://www.bleepingcomputer.com/news/security/ascension-hacked-after-employee-downloaded-malicious-file/","publisher":"BleepingComputer"},{"title":"Ascension cyberattack exposes data from 5.6 million people","url":"https://www.healthcaredive.com/news/ascension-cyberattack-data-breach-5-6-million/736167/","publisher":"Healthcare Dive"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-ascension-ransomware-attack-began-when-an-employee-downloaded-a-maliciou"},{"title":"WHO impersonation surge during COVID-19 targets donors and staff","date":"2020-04-23","date_precision":"day","victim_org":"World Health Organization and the general public (multi-victim campaign)","sector":"Healthcare","country":"Global","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported in 2020.","outcomes":["Credential Theft","Wire Fraud / Financial Loss","Data Breach"],"loss_usd":null,"loss_note":"WHO did not publish a total for donations diverted by impersonators.","records_affected":450,"threat_actor":null,"summary":"On 23 April 2020 the World Health Organization reported a more than fivefold increase in cyber attacks directed at the agency and warned the public about scammers impersonating WHO. Around 450 active WHO email addresses and passwords were leaked online, alongside thousands of credentials belonging to others working on the coronavirus response. WHO said fraudsters were posing as the organization and as the COVID-19 Solidarity Response Fund, and sending invoices requesting payment on the Fund's behalf.","how_it_worked":"Attackers exploited the single most trusted authority of the moment. Emails carrying WHO branding promised guidance on the outbreak and asked recipients to click through to a credential capture page or open an attachment, and separate campaigns solicited donations to a fake version of the COVID-19 Solidarity Response Fund or issued invoices purporting to come from it. The lever was fear plus civic goodwill under acute uncertainty, when recipients were actively seeking official pandemic information and wanted to help. The leaked credentials came from an older extranet system used by current staff, retired employees and partners.","lessons":"Legacy extranets holding partner credentials must be retired or moved behind modern multi-factor authentication, and public-facing agencies should publish a single authoritative donation channel to make impersonation obvious.","confidence":"Confirmed","sources":[{"title":"WHO reports fivefold increase in cyber attacks, urges vigilance","url":"https://www.who.int/news/item/23-04-2020-who-reports-fivefold-increase-in-cyber-attacks-urges-vigilance","publisher":"World Health Organization"},{"title":"Cyber security: beware of criminals pretending to be WHO","url":"https://www.who.int/about/cyber-security","publisher":"World Health Organization"}],"entry_type":"campaign","slug":"2020-who-impersonation-surge-during-covid-19-targets-donors-and-staff","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-who-impersonation-surge-during-covid-19-targets-donors-and-staff"},{"slug":"2020-magellan-health-ransomware-began-with-a-phishing-email-impersonating-a-c","title":"Magellan Health ransomware began with a phishing email impersonating a client","date":"2020-04-06","date_precision":"day","year":2020,"victim_org":"Magellan Health","sector":"Healthcare","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Vendor / Supply Chain Impersonation","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Ransomware Deployment","Data Breach","Credential Theft","Extortion"],"loss_usd":1430000,"loss_kind":"business_impact","loss_note":"US$1.43 million class-action settlement resolving claims over the breach and the delay in notification.","records_affected":364892,"threat_actor":null,"summary":"Magellan Health, a US managed care and behavioral health company, was hit by ransomware on 11 April 2020. The investigation traced the intrusion to 6 April, when an employee responded to a spear-phishing email in which the attacker impersonated a Magellan client. Before encrypting files the attackers stole employee data and deployed credential-harvesting malware. At least 364,892 individuals across Magellan subsidiaries and partner organisations were affected.","how_it_worked":"The attacker impersonated one of Magellan's own clients, which is a stronger pretext than a generic executive spoof because a managed care company's staff correspond with client organisations constantly and are expected to be responsive to them. The employee provided access credentials in response to that message. Over the following five days the attackers moved through the network, reached a corporate server holding employee records including tax documentation with Social Security numbers, exfiltrated a subset of it, and installed software to harvest further log-ins before triggering encryption. The five-day dwell time is where the data theft happened.","lessons":"Client-impersonation phishing defeats seniority-based suspicion, so the control is MFA plus detection of internal reconnaissance in the days between the click and the encryption.","confidence":"Confirmed","sources":[{"title":"Data Stolen in Magellan Health Ransomware Attack","url":"https://www.hipaajournal.com/magellan-health-suffers-ransomware-attack/","publisher":"HIPAA Journal"},{"title":"Healthcare giant Magellan Health hit by ransomware attack","url":"https://www.bleepingcomputer.com/news/security/healthcare-giant-magellan-health-hit-by-ransomware-attack/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-magellan-health-ransomware-began-with-a-phishing-email-impersonating-a-c"},{"slug":"2019-presbyterian-healthcare-services-phishing-exposes-data-on-183-000-patien","title":"Presbyterian Healthcare Services phishing exposes data on 183,000 patients","date":"2019-05-09","date_precision":"day","year":2019,"victim_org":"Presbyterian Healthcare Services","sector":"Healthcare","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":183000,"threat_actor":null,"summary":"New Mexico's largest health system, Presbyterian Healthcare Services, disclosed in August 2019 that a phishing attack had given attackers access to employee email accounts beginning around 9 May 2019, detected on 6 June. The compromised mailboxes held the information of approximately 183,000 patients and health plan members, including names, dates of birth, Social Security numbers and clinical and insurance details. Presbyterian later settled class-action litigation over the incident.","how_it_worked":"Attackers sent phishing emails to Presbyterian staff that led to a page requesting their work credentials. Staff who entered their username and password gave the attackers direct log-in access to the organisation's email system, with no malware involved and nothing unusual for endpoint tools to detect. Access ran for about four weeks before it was found. As with most healthcare mailbox compromises, the exposure came from the ordinary contents of clinical and administrative inboxes, which routinely carry patient identifiers, diagnoses, insurance data and Social Security numbers in message bodies and attachments.","lessons":"Multi-factor authentication on webmail is the single control that turns a harvested healthcare password into a dead end.","confidence":"Confirmed","sources":[{"title":"Phishing Attack on Presbyterian Healthcare Services Exposed PHI of 183,000 Patients","url":"https://www.hipaajournal.com/phishing-attack-on-presbyterian-healthcare-services-exposed-phi-of-183000-patients/","publisher":"HIPAA Journal"},{"title":"Presbyterian Healthcare phishing scam hits 183K patient records","url":"https://www.healthcareitnews.com/news/presbyterian-healthcare-phishing-scam-hits-183k-patient-records","publisher":"Healthcare IT News"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2019-presbyterian-healthcare-services-phishing-exposes-data-on-183-000-patien"},{"slug":"2018-unitypoint-health-phishing-of-executive-spoofed-emails-exposes-1-4-milli","title":"UnityPoint Health phishing of executive-spoofed emails exposes 1.4 million patients","date":"2018-03","date_precision":"month","year":2018,"victim_org":"UnityPoint Health","sector":"Healthcare","country":"United States","primary_vector":"Business Email Compromise","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft"],"loss_usd":2800000,"loss_kind":"business_impact","loss_note":"US$2.8 million class-action settlement to resolve litigation over the breach.","records_affected":1400000,"threat_actor":null,"summary":"UnityPoint Health, an Iowa-based health system, disclosed in July 2018 that a phishing campaign had compromised multiple employee email accounts between 14 March and 3 April 2018, exposing data on approximately 1.4 million patients. It was the largest US health data breach reported that year. Investigators concluded the attackers were most likely trying to divert vendor or payroll payments rather than steal medical records.","how_it_worked":"The phishing emails were crafted to appear to come from an executive inside UnityPoint Health, which gave them the internal legitimacy that gets messages read and links clicked. Staff who followed the links and entered their credentials handed over access to their mailboxes, and the attackers used those accounts for about three weeks. The financial motive shows in what they did next: they hunted for vendor invoices and payroll processes to redirect. The patient data exposure, which included medical, insurance, Social Security and in some cases payment card details, was collateral, simply whatever happened to be sitting in the compromised inboxes.","lessons":"Multi-factor authentication on clinical staff email, and a policy against storing patient identifiers in mailboxes, would have limited both the access and the exposure.","confidence":"Confirmed","sources":[{"title":"1.4 million patient records breached in UnityPoint Health phishing attack","url":"https://www.healthcareitnews.com/news/14-million-patient-records-breached-unitypoint-health-phishing-attack","publisher":"Healthcare IT News"},{"title":"1.4 Million Patients Warned About UnityPoint Health Phishing Attack","url":"https://www.hipaajournal.com/unitypoint-health-phishing-attack-1-4-million-patients/","publisher":"HIPAA Journal"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-unitypoint-health-phishing-of-executive-spoofed-emails-exposes-1-4-milli"},{"title":"Anthem breach of 78.8 million records started with a spear phishing email","date":"2015-02-04","date_precision":"day","victim_org":"Anthem Inc.","sector":"Healthcare","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Espionage","Identity Theft"],"loss_usd":115000000,"loss_note":"Anthem agreed to a $115 million class-action settlement in 2017 and a $16 million HIPAA settlement with HHS OCR in 2018, plus a multistate settlement of about $39.5 million in 2020; the figure given is the class-action settlement only.","records_affected":78800000,"threat_actor":"China-linked espionage group (reported as Deep Panda / Black Vine; US DOJ later indicted Fujie Wang and others)","summary":"Anthem disclosed in February 2015 that attackers had taken records on 78.8 million current and former members, including names, dates of birth, Social Security numbers and employment data. A multistate insurance-regulator examination and subsequent reporting concluded the intrusion began when an employee at an Anthem subsidiary opened a spear phishing email, giving attackers a foothold that led to stolen administrator credentials and access to the enterprise data warehouse.","how_it_worked":"A targeted email delivered to at least one subsidiary employee installed a backdoor on the workstation. The attackers used that access to move laterally, harvest credentials and eventually obtain the credentials of database administrators, allowing them to query Anthem's data warehouse directly. Data was staged and exfiltrated over months to external infrastructure, including domains that typosquatted the company's former name. The activity was noticed only when an administrator saw a database query running under his own account that he had not issued.","lessons":"Privileged database accounts should require phishing-resistant MFA and behavioural monitoring, and bulk queries against member data warehouses should alert regardless of which account issues them.","confidence":"Confirmed","sources":[{"title":"Commissioner Jones Announces Examination Findings of Anthem Cyber Attack","url":"https://www.insurance.ca.gov/0400-news/0100-press-releases/anthemcyberattack.cfm","publisher":"California Department of Insurance"},{"title":"Anthem Data Breach: What Happened, Impact, and Lessons","url":"https://www.huntress.com/threat-library/data-breach/anthem-data-breach","publisher":"Huntress"},{"title":"The Anthem Hack: All Roads Lead to China","url":"https://threatconnect.com/blog/the-anthem-hack-all-roads-lead-to-china/","publisher":"ThreatConnect"}],"entry_type":"incident","slug":"2015-anthem-breach-of-78-8-million-records-started-with-a-spear-phishing-emai","year":2015,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2015-anthem-breach-of-78-8-million-records-started-with-a-spear-phishing-emai"},{"slug":"2014-premera-blue-cross-breach-began-with-a-spear-phishing-email-10-4-million","title":"Premera Blue Cross breach began with a spear-phishing email, 10.4 million affected","date":"2014-05","date_precision":"month","year":2014,"victim_org":"Premera Blue Cross","sector":"Healthcare","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Espionage"],"loss_usd":6850000,"loss_kind":"business_impact","loss_note":"US$6.85 million HIPAA penalty imposed by HHS Office for Civil Rights in 2020; separate class-action and multistate settlements followed.","records_affected":10400000,"threat_actor":null,"summary":"Attackers compromised Premera Blue Cross in May 2014 and remained undetected for about nine months until January 2015. The intrusion exposed the protected health information of roughly 10.4 million individuals, including names, dates of birth, Social Security numbers, bank account details and clinical information. The HHS Office for Civil Rights, describing the incident, stated that the entry point was a spear-phishing email that installed malware.","how_it_worked":"The intrusion started with a spear-phishing email sent to Premera staff which, when acted on, installed malware and gave the attackers an interactive foothold inside the health plan's network. From there they operated quietly for nine months, moving through systems that held member enrolment, claims and clinical data. The regulator's later findings emphasised that Premera had not run an adequate enterprise-wide risk analysis and lacked the monitoring that would have surfaced anomalous internal activity, which is why a single successful email turned into nine months of undetected access across a database of more than ten million members.","lessons":"Email filtering and user reporting only reduce the odds; the decisive control here was internal detection, since the damage came from nine months of unnoticed lateral movement.","confidence":"Confirmed","sources":[{"title":"OCR Imposes 2nd Largest Ever HIPAA Penalty of $6.85 Million on Premera Blue Cross","url":"https://www.hipaajournal.com/ocr-imposes-2nd-largest-ever-hipaa-penalty-of-6-85-million-on-premera-blue-cross/","publisher":"HIPAA Journal"},{"title":"Premera Blue Cross Breach Exposes Financial, Medical Records","url":"https://krebsonsecurity.com/2015/03/premera-blue-cross-breach-exposes-financial-medical-records/","publisher":"Krebs on Security"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2014-premera-blue-cross-breach-began-with-a-spear-phishing-email-10-4-million"}]}