AI News Feed
Market watch
Cybersecurity

Baylor Genetics cyberattack exposes data of 2.8 million patients and employees

Baylor Genetics confirmed a June cyberattack affecting 2.8 million people, with medical and financial data stolen. No misuse reported yet.

In a security update posted on its website this week, the company said it detected the intrusion in a “limited portion” of its IT environment on or around June 15. A subsequent investigation determined that both patients and employees had data stolen, including individuals no longer employed at Baylor.

For patients, the stolen information includes names, dates of birth, medical testing information, laboratory test results, and potentially health insurance information as well as Social Security numbers. Baylor Genetics stressed that Social Security numbers were taken from a “very limited subset” of patients.

For certain current and former employees, the attackers obtained Social Security numbers, government-issued identification numbers, and financial account information, which could be used for wire fraud.

The company did not disclose the identity of the attackers or the number of affected individuals in its security update. However, in a separate report filed with the US Department of Health and Human Services, Baylor reported the number of victims as 2,810,878. The company added that, as of the time of publication, there was no evidence of confirmed identity theft, fraud, or misuse of personal information stolen in the attack.

Baylor Genetics also said the incident did not impact its everyday operations, which continued as usual.

Typically, data theft incidents are followed by public disclosure from perpetrators seeking to pressure victims into paying a ransom. So far, no threat actor has claimed responsibility for this incident.

Baylor Genetics confirmed a cyberattack affecting 2.8 million individuals, with medical test results and financial data among the stolen information. No misuse has been detected yet, and no group has claimed responsibility.