Menu
Browse

Cyber Incident Victim: Shields Health Care Group

Date:

Apr 2022

Location:

United States of America

Summary

Shields Health Care Group experienced a cybersecurity incident involving unauthorized system access that compromised sensitive patient data, including personal and medical information. The breach impacted approximately two million individuals, with exposed details encompassing names, Social Security numbers, diagnoses, and treatment records. Unauthorized access occurred over a multi-week period before detection. The organization initiated breach notifications to affected parties and regulatory bodies, offering credit monitoring services to mitigate potential harm. This incident underscored vulnerabilities in healthcare sector data protection and risks associated with third-party service providers handling sensitive information.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The City of Portland, Oregon, experienced a cybersecurity incident in April 2022 resulting in a fraudulent transfer of $1.4 million in public funds. Preliminary investigations revealed an unauthorized external entity gained access to a city email account, which was then used to conduct the illegal transaction. The breach remained undetected until May 2022, when the same compromised account attempted another fraudulent transaction, prompting city officials to initiate an investigation. While specific technical details about the attack vector weren't disclosed, the pattern suggested a Business Email Compromise (BEC) scheme targeting municipal financial systems. This incident mirrored previous attacks against government entities, including a 2019 case where Portland Public Schools nearly lost $2.9 million to a similar contractor impersonation scam, though those funds were recovered through rapid detection.

Cyber Incident Image

City authorities issued a press release confirming the breach but provided no information about fund recovery efforts. Portland State University cybersecurity expert Wu-chang Feng expressed skepticism about recovering the stolen money due to the month-long detection delay, noting such funds typically become untraceable after extensive laundering through multiple accounts. The FBI's public advisories from earlier that month contextualized the attack, reporting $43 billion in global BEC losses between 2016-2021 across nearly 250,000 incidents. Historical precedents included Erie, Colorado's $1 million loss in 2019 through manipulated payment requests for infrastructure projects. Portland officials did not disclose whether enhanced security measures were implemented post-incident or specify which departments or systems were affected beyond the compromised email account. The financial impact represented a direct loss to municipal resources without immediate clarity on potential secondary consequences for city operations or constituent services.

Sources
Sources available to members
1 source