Security News > 2023 > February > Healthcare giant CHS reports first data breach in GoAnywhere hacks
The healthcare provider giant said on Monday that Fortra issued an alert saying that it had "Experienced a security incident" leading to some CHS data being compromised.
A subsequent investigation revealed that the resulting data breach affected the personal and health information of up to 1 million patients.
"While that investigation is still ongoing, the Company believes that the Fortra breach has not had any impact on any of the Company's information systems and that there has not been any material interruption of the Company's business operations, including the delivery of patient care," CHS said an 8-K filing with the SEC first spotted by DataBreaches.net.
Clop also said they had allegedly stolen the data over ten days after breaching GoAnywhere MFT servers vulnerable to exploits targeting the CVE-2023-0669 RCE bug.
At the time, the victims received emails demanding $10 million in ransoms to avoid having their data published on the cybercrime group's data leak site.
If Clop follows a similar extortion strategy, we will likely see a rapid release of data for non-paying victims on the threat actor's data leak site in the near future.
News URL
Related news
- 20 million Cutout.Pro user records leaked on data breach forum (source)
- Golden Corral restaurant chain data breach impacts 183,000 people (source)
- American Express credit cards exposed in vendor data breach (source)
- American Express credit cards exposed in third-party data breach (source)
- French unemployment agency data breach impacts 43 million people (source)
- 43 million workers potentially affected in France Travail data breach (source)
- Fujitsu found malware on several systems, confirms data breach (source)
- Fujitsu found malware on IT systems, confirms data breach (source)
- Fujitsu finds malware on company systems, investigates possible data breach (source)
- Yacht retailer MarineMax discloses data breach after cyberattack (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-02-06 | CVE-2023-0669 | Deserialization of Untrusted Data vulnerability in Fortra Goanywhere Managed File Transfer Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. | 7.2 |