Data Breaches

950,000 Impacted by Young Consulting Data Breach

The personal information of over 950,000 people was compromised in a BlackSuit ransomware attack on Young Consulting.

The personal information of over 950,000 people was compromised in a BlackSuit ransomware attack on Young Consulting.

Software solutions provider Young Consulting is notifying over 950,000 individuals that their personal information was compromised in a data breach earlier this year.

The incident was discovered on April 13, when the company “became aware of technical difficulties” within its environment.

“We immediately took certain systems offline to contain the incident and launched an investigation, with the assistance of a cybersecurity forensics firm, to determine the nature and scope of the event,” Young Consulting explains in a notification on its website.

The company discovered that the attackers had access to its network between April 10 and April 13, and that they copied files containing personal information, including names, dates of birth, Social Security numbers, insurance policy/claim information, prescriptions, and provider names.

According to the software maker, the compromised data belongs to health insurer Blue Shield of California and to “other covered entities”. Young Consulting provides integrated software solutions for medical stop loss organizations.

Blue Shield of California this week posted a notice on the incident, revealing that Young Consulting notified it of a data breach impacting “the health plan members’ information”.

Advertisement. Scroll to continue reading.

Young Consulting informed the Maine Attorney General’s Office that it has started sending written notification letters to 954,177 people. The company is offering one year of free credit monitoring services to the impacted individuals.

The software maker did not share further information on the affected entities, nor on the type of cyberattack it fell victim to.

In early May, however, the BlackSuit ransomware group added Young Consulting to its Tor-based leaks site, claiming the theft of business, employee, financial, and other types of data.

The cybercrime gang has since made the allegedly stolen information available for download, likely because the software provider did not give in to their extortion attempt.

Related: American Radio Relay League Paid $1 Million to Ransomware Gang

Related: Patelco Credit Union Says Breach Impacts 726k After Ransomware Gang Auctions Data

Related: Using Threat Intelligence to Predict Potential Ransomware Attacks

Related: New ‘Agenda’ Ransomware Customized for Each Victim

Related Content

Data Breaches

The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.

Data Breaches

The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact.

Data Breaches

Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform.

Data Breaches

Hackers used compromised credentials to access enterprise and personal tax-related data.

Data Breaches

Hackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information.

Data Breaches

The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.

Data Breaches

The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.

Data Breaches

Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version