Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

950,000 Impacted by Young Consulting Data Breach

The personal information of over 950,000 people was compromised in a BlackSuit ransomware attack on Young Consulting.

Software solutions provider Young Consulting is notifying over 950,000 individuals that their personal information was compromised in a data breach earlier this year.

The incident was discovered on April 13, when the company “became aware of technical difficulties” within its environment.

“We immediately took certain systems offline to contain the incident and launched an investigation, with the assistance of a cybersecurity forensics firm, to determine the nature and scope of the event,” Young Consulting explains in a notification on its website.

The company discovered that the attackers had access to its network between April 10 and April 13, and that they copied files containing personal information, including names, dates of birth, Social Security numbers, insurance policy/claim information, prescriptions, and provider names.

According to the software maker, the compromised data belongs to health insurer Blue Shield of California and to “other covered entities”. Young Consulting provides integrated software solutions for medical stop loss organizations.

Blue Shield of California this week posted a notice on the incident, revealing that Young Consulting notified it of a data breach impacting “the health plan members’ information”.

Young Consulting informed the Maine Attorney General’s Office that it has started sending written notification letters to 954,177 people. The company is offering one year of free credit monitoring services to the impacted individuals.

The software maker did not share further information on the affected entities, nor on the type of cyberattack it fell victim to.

Advertisement. Scroll to continue reading.

In early May, however, the BlackSuit ransomware group added Young Consulting to its Tor-based leaks site, claiming the theft of business, employee, financial, and other types of data.

The cybercrime gang has since made the allegedly stolen information available for download, likely because the software provider did not give in to their extortion attempt.

Related: American Radio Relay League Paid $1 Million to Ransomware Gang

Related: Patelco Credit Union Says Breach Impacts 726k After Ransomware Gang Auctions Data

Related: Using Threat Intelligence to Predict Potential Ransomware Attacks

Related: New ‘Agenda’ Ransomware Customized for Each Victim

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Hear from experts as they explore the latest trends, challenges and innovations in Attack Surface Management.

Register

Event: ICS Cybersecurity Conference

The leading industrial cybersecurity conference for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Register

People on the Move

Janet Rathod has been named VP and CISO at Johns Hopkins University.

Barbara Larson has joined SentinelOne as Chief Financial Officer.

Amy Howland has been named Partner and CISO at Guidehouse.

More People On The Move

Expert Insights