Menu
Browse
Date:

May 2023

Location:

United States of America

Summary

A data breach at the Illinois Department of Healthcare and Family Services exposed sensitive personal information of Medicaid, SNAP, and TANF beneficiaries through unauthorized accounts created in the state's benefits eligibility portal. Attackers leveraged externally stolen personal data to access and link to existing accounts within the Manage My Case system, compromising names, Social Security numbers, addresses, phone numbers, income details, and recipient identification numbers. The departments disabled unauthorized access, notified affected individuals and state authorities, and established an assistance line while advising impacted parties to utilize identity theft resources from consumer reporting agencies and the Federal Trade Commission. The incident underscores vulnerabilities in systems supporting critical public assistance programs.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On May 12, 2023, the Illinois Department of Healthcare and Family Services (HFS) and the Illinois Department of Human Services (IDHS) disclosed a data breach impacting the State of Illinois Application for Benefits Eligibility (ABE) system’s Manage My Case (MMC) portal. The breach involved unauthorized accounts created within the ABE system that accessed and linked to legitimate customer MMC accounts by exploiting personal information stolen from an external source. Attackers leveraged this stolen data to compromise accounts tied to Medicaid, the Supplemental Nutrition Assistance Program (SNAP), and Temporary Assistance for Needy Families (TANF) – the primary benefit programs administered through the ABE portal. Exposed information included names, Social Security numbers, recipient identification numbers, addresses, phone numbers, and income details. The breach potentially affected all individuals who had applied for or were actively receiving benefits through the ABE system, though the exact number of compromised accounts was not disclosed.

Cyber Incident Image

HFS and IDHS implemented containment measures to halt further unauthorized access and notified affected individuals, the Illinois General Assembly, and the Office of the Illinois Attorney General. They established a dedicated assistance line (1-877-657-0006) operational until August 14, 2023, to address inquiries. Impacted parties were advised to contact consumer reporting agencies to place fraud alerts or security freezes on their accounts and directed to the Federal Trade Commission’s identity theft resources. The incident underscored vulnerabilities in systems managing sensitive benefit program data, though no specifics regarding breach duration, intrusion methods, or attacker attribution were released. Consequences included heightened identity theft risks for beneficiaries reliant on state-funded medical, nutritional, and financial assistance programs.

Sources
Sources available to members
1 source