UnitedHealthcare notified members after credential stuffing attack on its mobile app

Organization
UnitedHealthcare
Exploit
Credential Compromise
Industry
Health Insurance

UnitedHealthcare told members in late April 2023 that an attacker had reached accounts on its mobile application earlier in the year. The insurer said it spotted suspicious activity on the app on February 22, 2023, and later concluded that the unauthorized access took place between February 19 and February 25.

The company said its investigation identified the activity as a credential stuffing attack, in which usernames and passwords stolen from unrelated services are replayed against a target's login pages. UnitedHealthcare said it found no evidence that the credentials used in the attack had been obtained from its own systems.

Information that may have been viewed included members' first and last names, health insurance member identification numbers, dates of birth, addresses, dates of service, provider names, claim information, and group names and numbers. The insurer said Social Security numbers, driver's license numbers and financial information were not involved.

UnitedHealthcare locked affected member portal accounts and forced a password reset. It said it determined on April 10 that personal information may have been affected, and notification letters began going out on April 28, 2023. The company offered two years of credit monitoring and identity protection at no cost. No total number of affected members was published at the time of reporting.

Sources