Cyber Incident Victim: Advocates Inc.
Date:
Sep 2021
Location:
United States of America
Summary
Advocates Inc., a Massachusetts-based nonprofit providing support services for individuals facing various life challenges, experienced a sophisticated cyberattack involving unauthorized network access and data theft. Sensitive patient and employee information, including names, Social Security numbers, health insurance details, diagnoses, and treatment records, was compromised during the breach affecting over 68,000 individuals. The organization engaged cybersecurity experts, reported the incident to federal authorities, and offered affected parties complimentary credit monitoring services despite no confirmed misuse of the stolen data.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Advocates Inc., a Massachusetts-based nonprofit organization providing support services for individuals facing challenges such as addiction, autism, and mental health issues, experienced a cyberattack between September 14 and September 18, 2021. An unauthorized actor gained access to the organization's network and exfiltrated files containing sensitive personal and health information. The breach was discovered on October 1, 2021, when Advocates was notified about the unauthorized network access. The organization engaged a cybersecurity firm to investigate the incident, which confirmed data theft occurred during the four-day intrusion period. The compromised files included names, addresses, dates of birth, Social Security numbers, health insurance details, client ID numbers, diagnoses, and treatment information belonging to both patients and employees. Advocates delayed notification while working to verify impacted individuals and collect current contact information.

The incident affected 68,236 individuals according to the breach report submitted to the HHS Office for Civil Rights. Advocates reported the attack to the Federal Bureau of Investigation and regulatory authorities but stated no evidence of attempted or actual misuse of stolen data had been identified. As a precautionary measure, the organization offered complimentary credit monitoring and identity theft protection services to affected individuals. The cybersecurity investigation revealed no additional details about the attackers' identity or methods beyond characterizing the incident as a sophisticated cyberattack resulting in confirmed data theft. Advocates implemented notification procedures consistent with regulatory requirements after completing their internal review and verification process.
