logo

Scam and credential theft activity spikes during open enrollment: What CISOs need to know

ID: 0cdfcc8a-0f33-545a-9063-65a8f1c3541e

STIX ID: report--0cdfcc8a-0f33-545a-9063-65a8f1c3541e

Feed Name: ThreatLocker Blog

Threat Score
70/100

Date Published: 2025-12-03

Date Updated: 2026-05-01

...
...

This report details the Cierant Corporation vendor breach in which an exploited vulnerability in the Cleo VLTrader file-transfer tool during the 2024 open enrollment period exposed names, addresses, dates of birth, medical and beneficiary identifiers for roughly 232,506 individuals; it connects that upstream supply-chain compromise to downstream personalized open-enrollment and Medicare scams, outlines legal consolidation of class actions, and offers hardening, vendor oversight, and detection controls for health plans and CISOs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.