CSIDB logo
Incident

GenRx Pharmacy

Incident posture

Attack window
Sep 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-28 00:00

Linked entities

Victim
GenRx Pharmacy
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

GenRx Pharmacy experienced a ransomware attack involving unauthorized access to its systems, which was promptly contained the same day it was detected. The attackers exfiltrated a limited set of files containing personal and protected health information—including patient names, contact details, medication lists, health plan data, and prescription information—from a small fraction of former patients, though no financial data or Social Security numbers were compromised. Following the incident, the organization implemented enhanced security measures such as firewall upgrades, multifactor authentication, intrusion detection systems, and employee training, while notifying regulatory authorities and credit reporting agencies.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 28, 2020, GenRx Pharmacy discovered evidence of ransomware on its systems during routine operations. The pharmacy immediately initiated an investigation by engaging independent information security and IT experts to conduct forensic analysis and incident response. Forensic evidence confirmed that unauthorized third parties had deployed the ransomware on September 27, 2020, one day prior to detection. The attackers gained access to a limited number of files containing protected health information before being expelled from the system on the same day as the discovery (September 28). GenRx maintained uninterrupted business operations throughout the incident due to unaffected backups and retained full access to its data. By November 11, 2020, investigators confirmed the cybercriminals had exfiltrated specific files containing personal and health information of former patients.

The compromised data included patient identifiers, transaction IDs, full names, addresses, phone numbers, dates of birth, genders, allergy information, medication lists, health plan details including member IDs, and prescription information. No Social Security Numbers or financial data were impacted, as GenRx did not collect or store such information. The breach affected fewer than five percent of former patients. In response, GenRx implemented multiple security enhancements including firewall firmware upgrades, additional antivirus and web-filtering software, multifactor authentication deployment, increased Wi-Fi network monitoring, employee cybersecurity training, and installation of real-time intrusion detection systems across all networked devices. The pharmacy notified affected individuals via first-class mail, provided a dedicated call center for inquiries, and reported the incident to federal and state regulatory authorities as well as Equifax, Experian, and TransUnion. No actual misuse of the exposed information had been identified at the time of notification.

Sources

Sources available to members: 1 source.

CSIDB