Cyber Incident Victim: Sound Generations
Date:
Jul 2021
Location:
United States of America
Summary
A nonprofit organization serving older adults and individuals with disabilities experienced two ransomware incidents where unauthorized actors encrypted files on its systems. The breaches compromised data belonging to over 100,000 individuals, including names, contact details, dates of birth, health insurance status, and potentially medical histories or insurance numbers for certain program participants. While forensic investigations could not confirm whether attackers accessed or acquired protected health information, the organization found no evidence of fraudulent misuse of the exposed data. It advised affected individuals to monitor accounts for suspicious activity and implemented significant cybersecurity enhancements following the attacks.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Sound Generations, a Seattle-based nonprofit providing healthcare resources to older adults and adults with disabilities, experienced two separate ransomware attacks in 2021. The first breach occurred on July 18, 2021, when unauthorized individuals accessed internal systems and encrypted files using ransomware. A second intrusion followed on September 18, 2021, employing identical encryption tactics. The organization promptly terminated both unauthorized accesses upon detection and engaged a third-party forensics firm to investigate the incidents. Forensic analysis confirmed the ransomware events but could not determine whether attackers viewed or exfiltrated protected health information during either intrusion. Sound Generations maintained operations as Washington state's largest aging services provider throughout both security events.

An internal review revealed that systems compromised in the attacks contained protected health information for 103,576 individuals. Exposed data included names, addresses, phone numbers, email addresses, dates of birth, and health insurance status details. Participants in the EnhanceFitness program faced additional exposure risks involving health insurance numbers, while broader health histories and medical conditions were potentially compromised if previously shared with the organization. Although no evidence of fraudulent information misuse emerged, Sound Generations notified affected individuals about potential risks and advised vigilance regarding account activity and insurance statements. The nonprofit implemented significant cybersecurity control enhancements following the dual incidents to strengthen system protections against future attacks.
