logo

CMS Sending Letters to 103,000 Medicare beneficiaries whose info was involved in a Medicare.gov breach.

ID: 8155e3c8-3499-5385-b6c0-98dd92055141

STIX ID: report--8155e3c8-3499-5385-b6c0-98dd92055141

Feed Name: DataBreaches.Net

Threat Score
70/100

Date Published: 2025-07-01

Date Updated: 2026-04-19

Author: Dissent

...
...

CMS reports that malicious actors used beneficiary data from unknown external sources to create fraudulent Medicare.gov accounts between 2023 and 2025, potentially exposing PHI for about 103,000 beneficiaries. After detecting the issue on May 2, 2025, CMS deactivated affected accounts, blocked new account creation from foreign IPs, is monitoring for suspicious claims, and is issuing new Medicare cards with new MBIs while advising beneficiaries to review statements and report suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.