CSIDB logo
Incident

American Osteopathic Association

Incident posture

Attack window
Jun 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-30 00:00

Linked entities

Victim
American Osteopathic Association
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The American Osteopathic Association experienced a cyberattack compromising personal data including names, Social Security numbers, financial account details, dates of birth, addresses, and login credentials. Following suspicious system activity, the organization initiated an investigation revealing unauthorized access and exfiltration of sensitive information affecting over 27,000 individuals. Notification delays were attributed to pandemic-related operational challenges hindering timely identification of impacted parties. The association offered affected individuals complimentary credit monitoring services and reported no evidence of malicious misuse of the stolen data at the time of disclosure.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 25, 2020, the American Osteopathic Association (AOA), a Chicago-based non-profit representing approximately 151,000 osteopathic physicians and medical students, detected suspicious activity on its systems. This prompted immediate containment measures, including network shutdown, followed by engagement of computer forensic specialists to investigate the security incident. The forensic analysis confirmed unauthorized actors had breached systems containing personally identifiable information and successfully exfiltrated data. Subsequent review determined the compromised information included names, addresses, dates of birth, Social Security numbers, financial account details, email addresses, usernames, and passwords. The AOA completed its assessment of impacted individuals by June 1, 2021, identifying 27,485 affected persons across the United States, including 209 residents of Maine.

Notification letters began mailing in October 2021, nearly sixteen months after initial detection, with the AOA attributing delays to operational challenges caused by the COVID-19 pandemic. The organization cited staff working conditions and physical access limitations as primary factors hindering timely identification of affected parties. Impacted individuals were offered one year of complimentary credit monitoring services. In its breach report filed with Maine’s attorney general on October 13, 2021, the AOA stated it had no evidence of actual or attempted malicious use of the stolen data. The incident exposed sensitive personal and financial information but did not disrupt the organization’s broader operational capacity to serve its membership base.

Sources

Sources available to members: 1 source.

CSIDB