CSIDB logo
Incident

Onyx Technologies

Incident posture

Attack window
Mar 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-20 00:00

Linked entities

Victim
Onyx Technologies
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Onyx Technology experienced a ransomware attack involving unauthorized access or potential removal of a server over a three-month period, discovered in late June. The breach compromised sensitive personal and medical information of nearly 97,000 individuals, including names, dates of birth, addresses, contact details, insurance identifiers, Medicare numbers, service dates, and healthcare provider names. The organization regained system control in early July and notified affected clients, patients, and regulatory authorities, though the specific ransomware group responsible remained unidentified with no public claims of involvement.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Onyx Technology, a Maryland-based firm, discovered a ransomware incident on June 28, 2022, following an investigation that revealed unauthorized access to or potential removal of a server between March 29 and June 28 of that year. The company restored access to its systems by July 7, 2022. On August 12, Onyx began notifying regulators, including the Montana Attorney General’s Office on behalf of Independent Care Health Plan (iCare), and affected individuals about the breach. The compromised server contained sensitive patient and client information, including names, dates of birth, addresses, phone numbers, iCare member ID numbers, Medicare ID numbers, dates of service, and providers’ names. Onyx reported the incident to the U.S. Department of Health and Human Services (HHS), indicating 96,814 affected individuals, though it remained unclear whether this figure represented all impacted entities or only specific clients like iCare.

DataBreaches.net contacted Onyx for clarification regarding the server’s removal and the identity of the ransomware group involved but received no response. The company published a substitute breach notice on its website after DataBreaches’ inquiry, reiterating the ambiguous language about the server’s status. No ransomware group claimed responsibility for the attack, and the incident did not appear on any leak sites as of the article’s publication date. Onyx’s notifications did not confirm whether data was exfiltrated or encrypted, nor did they disclose the attack’s operational impact beyond the server compromise. A post-publication correction clarified that Onyx discovered the breach on June 28, not June 12 as initially stated. The incident exposed healthcare-related personal information but yielded no public evidence of further misuse or additional technical details regarding the attackers’ methods.

Sources

Sources available to members: 1 source.

CSIDB