Menu
Browse

Cyber Incident Victim: Aurora Medical Center Bay Area

Date:

Jan 2020

Location:

United States of America

Summary

Aurora Medical Center Bay Area experienced a cybersecurity incident involving unauthorized access to employee email accounts via a phishing scam. The breach potentially compromised patients' personal information, though the healthcare provider did not specify the exact scope or types of data exposed. Advocate Health Aurora confirmed the incident and indicated that hackers exploited email credentials through deceptive tactics. No further details regarding mitigation or forensic findings were disclosed in the initial report.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In early January 2020, Aurora Medical Center Bay Area experienced a cybersecurity incident involving unauthorized access to employee email accounts. Attackers executed an email phishing scam around January 1 that successfully compromised multiple staff accounts at the Marinette-based healthcare facility. Advocate Health Aurora, the parent organization, confirmed the breach but did not disclose how many accounts were infiltrated or the exact duration of unauthorized access. The compromised email systems potentially contained sensitive patient information, though the hospital did not specify whether medical records or financial data were exposed. There is no indication in available reports that ransomware was deployed or that clinical operations were disrupted during this incident.

Cyber Incident Image

Advocate Health Aurora initiated an investigation upon detecting the phishing attack, securing the affected email accounts to prevent further unauthorized access. By April 17, 2020, the organization began notifying patients that their personal information might have been accessed during the breach, though they did not publicly confirm whether data was actually exfiltrated. The hospital offered free credit monitoring services to impacted individuals as a precautionary measure. No details were provided about law enforcement involvement, forensic methodology, or specific security improvements implemented post-incident. The disclosure emphasized that the breach originated through employee email accounts rather than direct penetration of medical databases or electronic health record systems.

Sources
Sources available to members
1 source