Virtual Event Now Live: Zero Trust Strategies Summit! - Login for Access
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Wisconsin Insurer Discloses Data Breach Impacting 950,000 Individuals

Wisconsin Physicians Service Insurance Corporation says the personal information of 950,000 people was stolen in the MOVEit hack last year.

Wisconsin Physicians Service Insurance Corporation (WPS) is notifying roughly 950,000 individuals that their personal information was stolen in the MOVEit campaign last year.

The MOVEit hack was disclosed in May 2023, after Progress Software discovered that the Russian-speaking Cl0p ransomware group had exploited a zero-day in the MOVEit Transfer managed file transfer (MFT) software to access customer data.

According to cybersecurity firm Emsisoft, close to 2,800 organizations were affected by the hack. The attackers stole the personal information of roughly 96 million people.

On September 6, WPS revealed impact from the MOVEit hack, announcing that 946,801 Medicare beneficiaries in the US were likely affected, including some Centers for Medicare & Medicaid Services (CMS) beneficiaries.

In a notification letter mailed to the impacted individuals, WPS explains that its 2023 investigation into the incident did not find “any evidence that an unauthorized party obtained copies of files that were within the WPS MOVEit application”.

A second investigation, launched in May 2024 with assistance from a third-party cybersecurity firm, discovered that files were indeed stolen from WPS’s MOVEit file transfer system, and that some of these files included personal information.

The compromised information, WPS says, includes names, addresses, dates of birth, Social Security numbers, gender, hospital account number, dates of service, and Medicare beneficiary identifier or health insurance claim number.

“CMS and WPS are not aware of any reports of identity fraud or improper use of your Personal Information as a direct result of this incident,” WPS’s notification letter reads. Medicare cards with new numbers will be issued where Medicare beneficiary identifiers were compromised.

Advertisement. Scroll to continue reading.

The insurer is providing the affected individuals with one year of credit monitoring and identity protection services and encourages them to remain vigilant of fraud attempts.  

Related: 500k Impacted by Texas Dow Employees Credit Union Data Breach

Related: Avis Data Breach Impacts 300,000 Car Rental Customers

Related: Every “Thing” Everywhere All at Once

Related: Home Depot Agrees to $17.5 Million Settlement With States Over 2014 Data Breach

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join SecurityWeek and Hitachi Vantara for this this webinar to gain valuable insights and actionable steps to enhance your organization's data security and resilience.

Register

Event: ICS Cybersecurity Conference

The leading industrial cybersecurity conference for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Register

People on the Move

Threat intelligence firm Intel 471 has appointed Mark Huebeler as its COO and CFO.

Omkhar Arasaratnam, former GM at OpenSSF, is LinkedIn's first Distinguised Security Engineer

Defense contractor Nightwing has appointed Tricia Fitzmaurice as Chief Growth Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.