Menu
Browse

Cyber Incident Victim: Interstitial Cystitis Network

Date:

Apr 2015

Location:

United States of America

Summary

A California-based health organization experienced a payment card breach affecting customers who placed orders through its online sales portal over several months. The compromise exposed names, addresses, phone numbers, email addresses, and full payment card details including CVV codes. An investigation determined the breach originated from a vendor’s stolen credentials rather than a direct intrusion into the organization’s systems, prompting a system-wide password reset. The organization’s president confirmed personal payment card information was also compromised and condemned the attack targeting medically vulnerable patients.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The Interstitial Cystitis Network (ICN), a California-based organization, began notifying customers of a payment card breach on October 26, 2015, following reports from customers who discovered their payment cards had been compromised. The breach impacted ICN’s Mail Order Center website (www.icnsales.com) between April 6, 2015, and October 1, 2015. Customers who placed orders during this seven-month period potentially had their name, address, phone number, email address, and payment card information exposed, including card numbers, expiration dates, and CVV codes. ICN confirmed the compromise occurred through a third-party vendor rather than a direct breach of their own systems. The organization initiated an investigation after being alerted by affected customers, leading to the discovery that an unnamed vendor’s password had been stolen, enabling unauthorized access to payment data.

Cyber Incident Image

In response to the breach, ICN reset all passwords associated with their systems to prevent further unauthorized access. Jill Osborne, ICN’s President and Founder, acknowledged the violation in a customer notification letter, emphasizing that the attackers targeted a website serving vulnerable patients dealing with pain and distress. Osborne disclosed that her personal credit card was also compromised during the incident, expressing solidarity with affected customers and apologizing for the inconvenience. The organization directed customers with questions or concerns to contact Osborne directly via phone, providing her personal contact number as a point of accountability. No evidence suggested data misuse beyond the initial card compromises, and ICN’s internal systems retained integrity throughout the incident.

Sources
Sources available to members
1 source