Sensitive data breached in ransomware attack on Alabama Board of Nursing personnel systems | #ransomware | #cybercrime


The Alabama Board of Nursing is warning nurses to change their passwords and monitor for identity theft after confirming their sensitive data may have been breached in a recent ransomware attack.

The Board announced Saturday that a “comprehensive forensic investigation” found suspicious server activity in August, with further malicious activity through September 1. Systems were immediately taken offline, and the exposure contained, but an unknown amount of sensitive personnel data was breached.

“Prompt containment actions successfully prevented this ransomware attack from further escalation, but investigators confirmed that some data was collected and downloaded,” the Board said. “…the Board has reason to believe that data containing Sensitive Personally Identifying Information and/or Protected Health Information may have been exposed. This data environment could have included information such as licensee names, dates of birth, Social Security numbers, driver’s license numbers, professional licensing information, and medical information.”

Since the attack knocked systems offline, nurses have no way to renew their licenses, while new nursing graduates must fill out their applications by hand.

SEE: Alabama Nursing Board’s systems still down following cyberattack, forcing delays, leaving 80,000 nurses with no way to renew licenses

The Board said it was cooperating with the Federal Bureau of Investigation and the Alabama Law Enforcement Agency and taking steps to restore systems and defend against future attacks.

The Board recommended nurses take the following protective measures against identity theft and fraud:

  • Be alert for phishing and impersonation attempts. Use extra caution with unexpected emails, text messages, or telephone calls about nursing licenses, renewals, fees, account verification, this cybersecurity incident, refunds, investigations, or credit monitoring. Do not click unexpected links, open unverified attachments, or provide personal info.
  • Use strong, unique passwords. Immediately change the password for any personal or employment account where you reused the same or a similar password associated with your Board-related portal. Do not reuse passwords across government, banking, personal email, and social media platforms.
  • Enable multifactor authentication (MFA). Turn on MFA wherever available, particularly for your primary email, financial, healthcare, and employment accounts.
  • Review financial and identity-related activity. Regularly monitor bank statements, credit card statements, credit reports, insurance explanations of benefits (EOBs), and tax accounts for any unauthorized or unrecognized activity.
  • Consider a credit freeze or fraud alert. A credit freeze is free, does not affect your credit score, and prevents unauthorized individuals from opening new accounts in your name. Alternatively, a fraud alert warns potential creditors to perform extra identity verification. You may also wish to commence credit monitoring or ID theft protections offered by third parties.
  • Report suspected identity theft. If you discover unauthorized transactions or suspect identity theft, notify your financial institution immediately. You can also file a formal report and receive a customized recovery blueprint through the Federal Trade Commission’s official resource at IdentityTheft.gov.
  • Individuals should rely only on verified updates published on the Alabama Board of Nursing Official Website. The Board will never proactively ask you to provide account credentials or passwords via email, text message, or unsolicited phone calls. The Board will issue additional individual notices or public updates as new material facts or further statutory reviews dictate.

To connect with the story’s author or, email [email protected] or find him on X and Facebook.

The 1819 Newsletter

Enter your email below to get our top stories delivered straight to your inbox every weekday morning.





Click Here For The Original Source.

——————————————————–

..........

.

.