CSIDB logo
Threat actor

Montefiore Medical Center employee

Attribution profile

Type
Insider - Disgruntled
Location
United States of America
Known incidents
1 incident
First seen
2018-01-01
Last seen
2018-01-01
Updated
2026-07-31 03:31
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is known publicly by the aliases “Former Montefiore Medical Center employee” and “Montefiore Medical Center employee,” reflecting the individual’s prior employment status at the institution. Geographically, the actor operated within the United States, affiliated with the Montefiore Medical Center network. Employment termination followed the discovery that the individual had accessed patient records without proper authorization, compromising the personal information of approximately four thousand patients. Investigative findings indicated that the unauthorized access persisted for an extended timeframe, with evidence suggesting the activity began in January 2018 and continued until the breach was identified in July 2020. After concluding an internal review, Montefiore Medical Center issued notifications to all affected individuals and formally severed the employment relationship with the responsible party.

The actor’s targeting was confined to the healthcare sector, focusing on a major medical center that provides clinical services across the United States. The tactics employed involved the misuse of legitimate employee credentials to obtain privileged access to electronic health record systems, enabling the individual to view and copy sensitive patient data without deploying malicious software or external hacking tools. Throughout the incident, no references were made to specific malware families, exploit kits, or command‑and‑control infrastructure, indicating that the breach relied solely on insider access rather than technical exploitation. Attribution analysis found no public connection to nation‑state sponsors, criminal consortia, or other organized threat groups; the activity is attributed exclusively to the individual’s actions as an insider. The episode represents a notable insider‑threat case within healthcare, wherein the compromise of roughly four thousand patient records underscored the risks posed by privileged internal users and prompted renewed scrutiny of access monitoring and data protection controls within medical institutions.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB