SundaySky notifies 37,095 people after files copied from its cloud servers
- Organization
- SundaySky Inc.
- Exploit
- Hacking
- Industry
- Marketing Technology
SundaySky Inc., a New York based company that builds personalised marketing and customer communication videos for corporate clients, told 37,095 people in March 2023 that their information had been taken from its systems.
The company said an unauthorised party reached its cloud based server environment in the United States and copied files between 6 and 8 January 2023, with the intrusion detected on 8 January. The files held health plan member information that a client had supplied to SundaySky between December 2018 and January 2019.
The exposed fields were narrow: a first name, a personal email address, and health savings account details including the effective date, the deductible and information relating to copayments. No clinical records were reported as involved. SundaySky filed the incident with the Department of Health and Human Services Office for Civil Rights and began sending notification letters on 7 March 2023.
SundaySky said it secured its environment, brought in investigators to determine what had been taken, contacted federal law enforcement and put additional technical safeguards in place for its cloud infrastructure. The company did not publicly identify the health plan whose members were affected, and did not say whether the intruder had been identified.