Aetna
Incident posture
Timeline
Summary
Aetna experienced a data breach in 2025 involving unauthorized access or disclosure via mailings, affecting 10,888 individuals.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In 2025, Aetna, a Hartford, Connecticut-based health insurance provider owned by CVS Health, experienced multiple data security incidents that together affected more than 11,600 individuals. Reports describing the breaches were filed with the U.S. Department of Health and Human Services Office for Civil Rights on February 27 of the following year. Two filings described incidents involving unauthorized access or disclosure: one affecting 10,888 people and another affecting 775. According to a spokesperson for CVS Health, the filings related to incidents that occurred in 2025 involving mailings sent by Aetna on behalf of two health plans. An error in the mailing distribution process resulted in letters being sent to members that may have included an individual who was not part of their health plan, as described by Shelly Bendit, senior manager of corporate communications for CVS Health.
The second major incident of 2025 involved a phishing email that led to an outside party gaining access to protected information. Aetna announced in January of the following year that it had completed its investigation into a data security incident that occurred on July 1, 2025. The phishing attack enabled the unauthorized party to access individuals' names and demographic information, medical provider names, health insurance information, and medication information. Following the discovery of the breach, Aetna notified affected individuals and offered complimentary credit monitoring services to those impacted. The company also reported that it implemented and enhanced safeguards and security measures designed to protect its email systems and rolled out enhanced employee training focused on recognizing and responding to phishing emails.
Aetna stated publicly that the protection of privacy and security of members' information is a top priority for the organization. Bendit said Aetna places the highest priority on protecting members' privacy and expressed regret that the situation occurred. The combination of the mailing distribution errors and the phishing-related unauthorized access produced the total reported impact of more than 11,600 affected individuals across the two separate filings.
Sources
Sources available to members: 1 source.