Mom's Meals discloses ransomware breach affecting more than 1.2 million people
- Organization
- Mom's Meals (PurFoods, LLC)
- Exploit
- Ransomware
- Industry
- Healthcare Services
PurFoods, which operates the medically tailored meal delivery service Mom's Meals, disclosed a data breach affecting more than 1.2 million people. The company said an intruder had access to its network between January 16 and February 22, 2023, and that it detected suspicious activity on February 22.
PurFoods said certain files on its systems had been encrypted and that tools commonly used to steal data were found on the network, indicating a ransomware attack. It said it could not rule out that data had been taken from one of its file servers. The company completed its review of the affected files on July 10, 2023.
The exposed information varied by individual and included names, dates of birth, Social Security numbers, driver's licence and state identification numbers, financial account and payment card details, medical record numbers, health insurance information, patient identifiers, diagnosis and treatment information, and meal categories and costs. Those affected included customers, current and former employees, and independent contractors.
Notification letters went out from around August 25, 2023, roughly six months after the intrusion was detected. The company filed notice with the Maine attorney general, reported the incident to the US Department of Health and Human Services and the major credit bureaus, and offered 12 months of credit monitoring through Kroll. TechCrunch reported that PurFoods had added code to its breach notice page instructing search engines not to index it. The company did not say how the attackers got in or which ransomware was used.