Menu
Browse

Cyber Incident Victim: Solara Medical Supplies

Date:

Apr 2019

Location:

United States of America

Summary

Solara Medical Supplies experienced a breach involving unauthorized access to employee email accounts via phishing attacks, compromising sensitive personal, medical, and financial data including names, addresses, Social Security numbers, and insurance details. The incident impacted current and former patients and employees, though the exact number of affected individuals was not disclosed. The company notified those involved, reset account credentials, and advised vigilance against potential identity theft or fraud.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Unauthorized actors gained access to employee Office 365 accounts at Solara Medical Supplies between April 2 and June 20, 2019, through successful phishing attacks. The breach persisted for nearly eleven weeks before detection, exposing sensitive personal, medical, and financial information. Compromised data included full names, physical addresses, Social Security numbers, protected health information related to medical conditions or treatments, and financial details. As a major national supplier of diabetes management equipment such as insulin pumps and continuous glucose monitors, Solara handled substantial volumes of sensitive patient data, though the exact number of affected individuals remained undisclosed in public disclosures. The incident impacted both current and former patients and employees whose information resided within the breached email accounts.

Cyber Incident Image

Solara initiated password resets for compromised accounts upon discovering the intrusion and notified affected individuals directly. The company advised vigilance regarding identity theft and fraud risks, specifically recommending scrutiny of financial statements, credit reports, and healthcare explanation of benefits documents. No additional technical containment measures or forensic methodology details were disclosed publicly. The breach exposed multiple data categories simultaneously—combining personally identifiable information, protected health records, and financial data—potentially enabling comprehensive identity theft or medical fraud against victims. Other healthcare entities, including Select Health Network, experienced similar email account breaches during overlapping timeframes, though Solara’s incident specifically stemmed from phishing rather than ransomware or indiscriminate system hacking.

Sources
Sources available to members
1 source