Data on the dark web
A notorious cybercrime cell—known for its deployment of ransomware—posted a notice on a dark web leak site in June, threatening to release a 234-gigabyte data trove it said was stolen from DentaQuest.
According to the hackers, it had data on more than 2.1 million patients in its possession, including sensitive medical records and information that could be used to identify individuals. The group posted screenshots as evidence their bounty is real.
DentaQuest did not confirm whether or not ransomware was deployed. The company has also not responded to claims made by ShinyHunters.
HealthExec reached out to the dental insurance administrator for comment.
It is unclear what happened to the data trove.
The hack was confirmed to have occurred between May 17 and May 20, meaning the unauthorized third party was inside the DentaQuest network for three days. The company said it worked with an outside cybersecurity firm to investigate the scope of the breach and to re-secure its systems.
“We have taken steps to further safeguard our systems, including enhancing our security and monitoring controls and providing additional employee training,” DentaQuest wrote.
Breach notices were sent to individuals beginning on July 17, the dental payer stated. Victims will be given complimentary access to identity theft protection and credit monitoring services, should they wish to sign up.
DentaQuest serves roughly 32 million dental and vision beneficiaries nationwide.
Click Here For The Original Source.
