Tusla began notifying 20,000 people whose data was stolen in the 2021 HSE attack
- Organization
- Tusla, Ireland's Child and Family Agency
- Exploit
- Third-Party Data Breach
- Industry
- Government
Tusla, Ireland's Child and Family Agency, said in February 2023 that it would contact about 20,000 people whose personal information was taken during the May 2021 ransomware attack on the Health Service Executive. The HSE supplied IT services to Tusla at the time, so agency records sat on the compromised systems.
For people who had dealings with Tusla, the exposed material included referrals made to the agency, reports, correspondence with service users, and contact details such as names, addresses and telephone numbers. For staff, it included HR records such as annual leave forms and travel expense claims.
Notification letters were sent by registered post from February 2023, and the agency expected the process to run for roughly ten months, into November 2023. Recipients were offered a choice between calling a dedicated support team on a freephone number, meeting a case worker in person, or reviewing the details of their own data through an online portal. People who did not receive a letter were told no action was needed.
Kate Duggan, Tusla's director of services and integration, said there was no evidence the information had been published on the internet or the dark web, or used in any fraudulent activity. A High Court order restricting the sharing or publication of the stolen data remained in place, and monitoring by cybersecurity experts continued.