400,000 Patients’ Information Compromised In Ransomware Attack

Exploit
Ransomware
Organization
Planned Parenthood
Industry
Healthcare, Non-Profit

 

An estimated 400,000 patients of Planned Parenthood had their information compromised by cybercriminals in what looks to be a ransomware attack. A Planned Parenthood Los Angeles spokesperson stated unauthorized network access was gained between October 9 and 17 as an undisclosed number of files were exfiltrated and malicious software was deployed.

Upon learning of the network intrusion, PPLA immediately acted by taking its systems offline. However, the threat actors were already able to install the ransomware payload and make off with the sensitive data.

After notifying law enforcement and working with third-party cybersecurity services, an investigation is underway. Thus far, the breach is said to have been limited to the Los Angeles affiliate and company officials are reassuring patients that there is no indication of the stolen information being “used for fraudulent purposes.”

The organization is letting patients know that compromised data includes names and “one or more of the following:” physical address, birth dates, medical information, insurance information, and prescription information.

Sources