Contact Contact Us

Hacked Email Accounts Leak Patient Records

A hospital in the US suffered a data breach when an unauthorised third-party hacked into several employee email accounts. The information stolen included names, Social Security Numbers, driver's license, dates of birth, health insurance and patient care information. It is unknown how the hackers compromise the email accounts, but a common tactic is through phishing, which redirects users to fake login page to steal login credentials. Hackers can also hijack users’ account through password spraying attacks (accounts secured with weak password) and credential stuffing attacks (password reuse across multiple online services).

References:
[1] Ernest Health Suffers Data Breach of Patient Records

Ensign InfoSecurity Singapore
30A Kallang Place
#08-01
Singapore 339213

Tel: +65 6788 2882
Fax: +65 6788 3883