CSIDB logo
Incident

University of California, Los Angeles

Incident posture

Attack window
Oct 2014
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-17 19:05

Linked entities

Victim
University of California, Los Angeles
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2014
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack compromised UCLA Health's network, exposing personal and medical data of approximately 4.5 million individuals. The breach involved sensitive information including names, addresses, Social Security numbers, medical conditions, medications, procedures, and test results, with the organization confirming the exposed data lacked encryption. While no evidence confirmed data exfiltration, the institution acknowledged it could not definitively eliminate that possibility, heightening risks of identity theft or misuse. Affected individuals were being notified, marking another significant healthcare sector breach following similar incidents impacting other major providers. The attackers remained unidentified, and the unencrypted nature of the stored data amplified potential consequences for victims.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On July 17, 2015, UCLA Health disclosed a cyberattack that compromised the personal and medical data of approximately 4.5 million individuals. The breach involved unauthorized access to a network containing sensitive information, including names, addresses, Social Security numbers, medical conditions, prescribed medications, procedures performed, and test results. UCLA Health stated it had no conclusive evidence that data was exfiltrated but acknowledged it could not definitively rule out data theft. The organization confirmed the exposed data was stored without encryption, significantly increasing potential risks for affected individuals, as unencrypted data could be readily exploited for identity theft or fraud. Notification efforts for impacted individuals were underway at the time of the announcement, though the specific timeline of the attack and its discovery remained undisclosed.

The incident marked one of several major healthcare sector breaches in 2015, following high-profile attacks on Anthem and Premera Blue Cross, which collectively exposed records of tens of millions of Americans. UCLA Health did not attribute the attack to any specific threat actor or nation-state, contrasting with the Anthem breach earlier that year, where the FBI investigated potential state-sponsored involvement. The lack of encryption drew particular scrutiny, as it left sensitive health data vulnerable despite industry warnings about cybersecurity vulnerabilities in medical systems. No ransomware or financial motive was cited in UCLA’s disclosure, distinguishing it from some contemporaneous healthcare breaches. The breach underscored systemic risks in healthcare data stewardship, with compromised information enabling long-term exploitation due to the static nature of identifiers like Social Security numbers and medical histories.

Sources

Sources available to members: 1 source.

CSIDB