iSpace notified consumers of a breach exposing Social Security and health data
- Organization
- iSpace, Inc.
- Exploit
- Hacking
- Industry
- Business Services
iSpace, Inc., a California based technology and business services company founded in 2000, notified consumers that an unauthorized party had accessed its network and copied files containing personal and health information.
According to the notice, iSpace detected suspicious activity within its computer systems on February 5, 2023. The subsequent investigation established that documents stored in its environment had been accessed and copied between January 30 and February 5, 2023. On March 3, 2023 iSpace determined that data may have been accessed or copied. Following further investigation and review of the data, it notified the organization whose information was found on April 3, 2023.
The compromised information varied by individual and included names, Social Security numbers, dates of birth, diagnosis information, health insurance group or policy numbers, health insurance information, subscriber numbers and prescription information. iSpace held the data in connection with services performed on behalf of other organizations, so those affected were not necessarily iSpace employees.
The company said it secured its network immediately on detecting the activity and launched an investigation. Notification letters were mailed on May 31, 2023, the same date iSpace filed a breach notice with the Montana Attorney General. The company also filed with the California Attorney General, whose listing records the breach dates but no number of affected residents. iSpace did not publish a total number of affected individuals, and no attacker was named.