Illinois healthcare agency reports phishing breach affecting 933 people

Organization
Illinois Department of Healthcare and Family Services
Exploit
Phishing
Industry
Government

The Illinois Department of Healthcare and Family Services disclosed in June 2025 that a phishing campaign had exposed the personal information of 933 people, 564 of them Illinois residents.

According to the agency, the campaign was identified on February 11, 2025. The messages were sent from a government email account that had already been compromised, which made them harder for staff to recognize. One employee interacted with the campaign, and the attacker gained access to that person's email and attached documents.

Information held in the affected mailbox included names, dates of birth, Social Security numbers, driver's license or state identification card numbers, child support and Medicaid case or identification numbers, and financial details tied to child support.

HFS said it worked with the Illinois Department of Innovation and Technology to block the malicious links and reset passwords for potentially affected employees, and that it distributed phishing awareness material to all staff. The agency completed notifications to affected individuals by May 23, 2025 and advised them to review their credit reports and consider fraud alerts or security freezes. The breach was made public on June 6, 2025, with the agency saying no further details were available at that point.

Sources