Illinois benefits portal breach exposed Medicaid, SNAP and TANF recipient data
- Organization
- Illinois Department of Healthcare and Family Services
- Exploit
- Credential Compromise
- Industry
- Government
The Illinois Department of Healthcare and Family Services and the Illinois Department of Human Services disclosed a breach of the Manage My Case portal within the state's Application for Benefits Eligibility system, known as ABE.
The departments said they discovered suspicious user accounts in the system on March 13, 2023. Whoever created those accounts used personal information obtained from an outside source to answer identity verification questions and link the new accounts to existing customer records, which gave them a view into individual benefit cases.
ABE determines eligibility for Medicaid, the Supplemental Nutrition Assistance Program and Temporary Assistance for Needy Families. Information visible through the portal included names, addresses, phone numbers, dates of birth, Social Security numbers, recipient identification numbers, individual and case identifiers, income details, and the benefits an applicant had sought or received. Where an application had been filed online, the application itself and any uploaded supporting documents could also be viewed, along with details of other people in the household.
The agencies said they deployed software to stop further suspicious account creation and unlinked the fraudulent accounts from customer records. They notified affected individuals, members of the Illinois General Assembly and the state Attorney General's office on May 12, 2023, and opened a dedicated assistance line that ran through August 14.
Neither department published a total number of affected residents.