Cybercrime
,
Data Breach Notification
,
Data Privacy
Baylor Genetics Among the Latest Medical Labs, Bio-Tech Firms Attacked
Genomics testing firm Baylor Genetics is notifying nearly 310,000 people and counting about a June hack that compromised sensitive patient information including test results and employee data. The incident is the latest in a rash of attacks hitting medical laboratories, biotech and life sciences firms.
See Also: OnDemand | Transform API Security with Unmatched Discovery and Defense
Baylor Genetics has so far reported to several state attorneys general that nearly 250,000 Texans were affected, as well as nearly 57,000 citizens in Massachusetts and more than 2,600 residents of Vermont.
Baylor Genetics in a breach notice said that it discovered suspicious activity on a limited portion of its IT environment around June 15.
An investigation into the incident determined that a threat actor accessed portions of Baylor Genetics’ network and certain stored data between June 11 and June 17.
Patient information potentially compromised varied by individual but may have included names, date of birth, medical testing information, laboratory test results, health insurance information, as well as Social Security number for a limited subset of individuals.
For current or former employees, the information potentially affected may have included personal identifying information such as Social Security numbers, government-issued identification numbers and financial account information.
“At this time, Baylor Genetics is not aware of any confirmed identity theft, fraud or misuse of personal information related to this incident,” the company said.
No cybercrime groups have surfaced on the darkweb claiming responsibility for the incident.
As its name implies, Baylor Genetics provides genetic testing and diagnostic services, including genomic sequencing, to uncover conditions related to rare diseases, pediatric genetics, reproductive health, hereditary cancer, metabolic disorders and other issues.

The company’s roots trace to 1978 when two physician-scientists founded the department of molecular and human genetics at Baylor College of Medicine. By 1996, the company was selected as one of six pilot sites for the final phases of the Human Genome Project, a research endeavor that has led to modern-day genomics discoveries.
Baylor Genetics did not immediately respond to ISMG’s request for additional details pertaining to its hacking incident.
The Baylor Genetics breach report comes on the heels of hacks on other medical laboratories, bio tech companies and med tech firms in recent weeks and months.
Similar Breaches
Other recent hacks include the theft of data from clinical testing laboratory and medical device maker Abbott Laboratories and its cancer diagnostics business Exact Sciences. Cybercrime gang ShinyHunters and another gang, ShadowByt3$, each claimed to steal data – including artificial intelligence models – from Abbott’s Exact Sciences unit (see: Craneware, Abbott Probe Separate Health Data Theft Incidents).
Also, cybercrime gang FulcrumSec in recent weeks claimed it leaked on its darkweb site two large caches of data the group claims it stole in a June attack on Novo Nordisk. The latest data dump allegedly includes the Danish drug maker’s “complete enterprise Hugging Face AI and machine learning ecosystem” (see: Extortion Gang Leaks Novo Nordisk ‘AI and ML Ecosystem’).
In addition to FulcrumSec’s claims, in June, a second hacker group, TheUSERS007, told Databreaches.net that it also stole “crown jewel” data – including AI models – from the maker of popular diabetes and weight loss treatment drugs Ozempic and Wegovy.
While healthcare sector entities have long been targeted by hackers, life sciences, medical testing and biotech companies and other such sectors are especially attractive targets for cybercriminals, some experts said.
“These organizations hold an unusually valuable combination of sensitive health information, personally identifiable information and, in some cases, proprietary research and intellectual property,” said Dave Bailey, vice president of solutions and strategy at healthcare privacy and security consultancy Clearwater.
“Genomic information is especially sensitive because, unlike a password or credit card number, it is inherently permanent. You cannot change your DNA after a breach.”
There could be several reasons for the apparent recent focus by cybercriminals on life- and bio-science firms, said Mike Hamilton, CISO emeritus at IT services firm Datec, Inc.
“First, they are regulated as a covered entity, and unauthorized disclosure of records brings regulatory action. Additionally, they house sensitive privacy and health information, and our privacy laws facilitate class action when those records are stolen,” he said. “Both of those facts give criminals substantial leverage when negotiating extortion demands.”
Hamilton said it’s unlikely that the kind of genetic testing information potentially stolen in the Baylor Genetics hack or similar incidents will be monetized by selling it on the darkweb, “although it may be interesting to some nation states that routinely steal research from American companies.”
Apart from the threat of regulatory action and civil litigation, hackers also pose additional risk to the integrity of the information compromised, he said. “If it can be stolen, it can be changed. This puts the victim organizations in an even worse position, unable to trust the veracity of their own data – which could have life-safety impacts,” he said. “Again, this gives the criminal organization a great deal of leverage.”
Organizations such as life sciences, medical labs and biotech companies should identify their most sensitive data and systems and apply protections commensurate with the consequences if those assets are compromised, Bailey said. “That means strong segmentation, least-privilege access, phishing-resistant multifactor authentication, encryption, rigorous third-party access controls and continuous monitoring for unusual access or data movement.”
Meanwhile, AI in the hands of hackers raises the stakes for these companies because it enables attackers to create more convincing phishing and social-engineering campaigns and operate at greater speed and scale, he said.
“Organizations should increasingly assume that credentials may eventually be compromised and build controls that prevent one compromised identity from becoming unrestricted access to sensitive data,” he said. “Just as importantly, they should regularly test their ability to detect, contain and recover from an attack rather than relying solely on preventative controls.”
Click Here For The Original Source.
