CSIDB logo
Threat actor

Former Geisinger Berwick employee

Attribution profile

Type
Insider - Accidental
Location
United States of America
Known incidents
1 incident
First seen
2019-06-03
Last seen
2019-06-03
Updated
2026-07-31 00:50
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is known publicly as a former Geisinger Berwick employee, an individual who worked within the organization’s clinic in Pennsylvania, United States of America. This alias reflects the insider nature of the activity, indicating that the actor possessed legitimate employment credentials and internal access to the healthcare provider’s systems. No additional aliases or alternative identifiers have been disclosed in the available sources. The actor’s location is confined to the United States, specifically the Geisinger Berwick facility in Pennsylvania, as noted in the incident report.

The actor’s targeting was limited to the healthcare sector, focusing on patient records held by Geisinger Berwick. The incident involved unauthorized viewing of protected health information, including names, dates of birth, Social Security numbers, medical conditions, treatment details, and contact information for more than seven hundred individuals. Investigators explicitly stated that there was no evidence of malicious intent, financial fraud, espionage, or disruptive objectives; the access lacked a valid business justification but was not linked to any known strategic goal such as profit, state‑sponsored intelligence gathering, or service interruption. Consequently, the actor’s motivations remain unspecified beyond the finding of improper access without harmful intent.

The actor’s tactics, techniques, and procedures consisted solely of exploiting legitimate employee privileges to view records; no malware, exploit tools, phishing, or external intrusion methods were referenced in the reporting. There is no indication of any tooling style, custom malware families, or specialized infrastructure associated with this activity. Attribution to a state actor, criminal consortium, or other organized group has not been established; the individual acted alone as a former workforce member. The sole publicly reported operation associated with this actor is the 2019‑2020 improper access incident at Geisinger Berwick, which led to the employee’s termination, internal notification of affected patients, and the provision of one year of free identity theft protection services as a precautionary measure. This case represents the entirety of the documented activity for this threat actor.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB