Young Consulting breach exposed data on 954,177 people, including Blue Shield members
- Organization
- Young Consulting
- Exploit
- Ransomware
- Industry
- Software
Young Consulting, a Georgia based software and risk management services provider that works with medical stop loss carriers, began notifying 954,177 people in late August 2024 that their personal information had been taken in an intrusion earlier in the year.
The company said an unauthorised party was present in its network between 10 and 13 April 2024 and copied files, and that it discovered the activity on 13 April. According to the breach notifications, including a filing with the Maine Attorney General, the affected files contained names, dates of birth, Social Security numbers, insurance policy and claim information, prescriptions and provider names.
The BlackSuit ransomware group added Young Consulting to its Tor leak site in early May 2024, claiming to hold business contracts, employee records including passport scans, and financial documents. The group said the company's leadership had refused to negotiate. The stolen data was subsequently made available for download on the group's site, which is consistent with a refusal to pay.
Blue Shield of California was among the affected clients. Young Consulting notified the insurer on 28 June 2024, and Blue Shield confirmed that a third-party vendor had experienced a security event that potentially affected health plan member information. Young Consulting offered those notified one year of complimentary credit monitoring. Several plaintiffs' firms announced investigations into the incident within days of the notices going out.