Menu
Browse

Cyber Incident Victim: National Capital Poison Center

Date:

Dec 2017

Location:

United States of America

Summary

The National Capital Poison Center experienced a ransomware incident potentially compromising decades of call records containing sensitive personal and medical information, including names, contact details, exposure specifics, and treatment recommendations. While the organization confirmed unauthorized encryption of its database server, it could not determine whether data was accessed or misused, noting most records contained only partial information subsets. No details were disclosed regarding ransom demands, payment, restoration attempts from backups, or the total number of affected individuals.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On or around December 11, 2017, the National Capital Poison Center (NCPC) disclosed a ransomware incident affecting its call center database. The attack compromised records spanning calls received between January 1, 1997, and October 21, 2017. While NCPC could not confirm whether attackers accessed or exfiltrated data, the exposed database contained sensitive health information provided during poison exposure consultations. This included caller names, names and birthdates of poison exposure victims, physical addresses, telephone numbers, clinical details of exposures, treatment recommendations, email addresses, and in some cases, treating facility names and medical record numbers. The center noted most call records contained only subsets of this information rather than complete datasets. NCPC did not specify the intrusion vector, initial detection method, or precise attack timeline beyond the broad 20-year data exposure window.

Cyber Incident Image

In its public notification, NCPC emphasized no reports of actual or attempted misuse of the exposed information had been received. The organization did not disclose whether it paid ransom demands or attempted system restoration from backups, nor did it reveal the total number of affected individuals. The notification omitted technical details about containment measures, forensic investigation methods, or whether decryption succeeded without payment. No information was provided regarding system downtime duration, operational impacts on poison hotline services, or whether third-party cybersecurity firms assisted in incident response. The disclosure focused exclusively on potential data compromise rather than attack remediation specifics or broader organizational consequences beyond the data exposure timeframe.

Sources
Sources available to members
1 source