Skip to content
NetarxImpact Database
Credential Phishing PortalNo AI reportedConfirmed

Phishing email compromises 53 LA County Public Health staff accounts, 200,000 affected

Los Angeles County Department of Public Health · Government · United States · February 19, 2024

People or records affected
200,000
200K as reported

What happened

The Los Angeles County Department of Public Health disclosed that between 19 and 20 February 2024 a phishing email compromised the log-in credentials of 53 employees, exposing the personal and health information of more than 200,000 individuals. Exposed data included names, dates of birth, Social Security numbers, diagnoses, prescriptions, health insurance and Medicare or Medi-Cal details. The same phishing campaign also hit LA County's Department of Health Services and Department of Mental Health.

How the deception worked

A phishing email circulated through the department and 53 separate employees entered their credentials on the attacker's page within roughly 24 hours, which shows the message was well matched to the environment rather than obviously fraudulent. With valid log-ins the attacker read the contents of those mailboxes, which in a county public health agency contain case correspondence carrying patient names, diagnoses, prescriptions and benefit identifiers. The department responded by disabling accounts, resetting devices, blocking the phishing sites and quarantining the messages, but by then two days of mailbox access across dozens of accounts had already occurred.

The control that would have caught it· our reading, not a claim from the sources

Phishing-resistant MFA across county staff accounts would have made the harvested passwords useless, and rapid cross-department alerting would have cut the exposure window.

Sources (2)

  1. 200,000 Impacted by Data Breach at Los Angeles County Public Health Agency
    SecurityWeek·securityweek.comOpen ↗
  2. Los Angeles Public Health Department Discloses Large Data Breach
    Infosecurity Magazine·infosecurity-magazine.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.