A rough day at the extortion office and a botched attack on Blossom Health.
ID: 2f6185b9-93b4-55cb-b2bd-6d39e4d25dc7
STIX ID: report--2f6185b9-93b4-55cb-b2bd-6d39e4d25dc7
Feed Name: DataBreaches.Net
*Executive summary:* A threat actor known as "Stuckin2019" claims to have accessed more than 29.6K Blossom Health patient records (names, DOBs, contact details and sensitive documents) and sent a $30,000 Bitcoin ransom demand directly via the provider-patient messaging portal; the actor says they gained access through an old staging environment that allowed production access, and evidence includes screenshots and email exchanges suggesting an active extortion/data exposure incident with potential HIPAA reporting requirements.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
