Menu
Browse

Cyber Incident Victim: Apex Laboratory, Inc.

Date:

Dec 2020

Location:

United States of America

Summary

Apex Laboratory, Inc. experienced a ransomware attack by the DoppelPaymer group, resulting in the exfiltration and public release of sensitive patient data including laboratory test results, diagnostic information, and extensive personal details such as Social Security numbers, Medicare/Medicaid identifiers, dates of admission/discharge, and demographic attributes. The breach impacted over 1,000 individuals across more than a dozen facilities, primarily involving outdated but exploitable records of elderly nursing home residents vulnerable to identity theft. Additionally, routine business documents were leaked, potentially exposing operational information. The organization did not publicly acknowledge the incident or respond to inquiries about the compromised data.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 2 techniques
Threat Actors Type Location
2 actors Available to members Available to members

Description

Apex Laboratory, Inc., a diagnostic testing service provider headquartered on Long Island with additional offices in south Florida, experienced a ransomware attack attributed to the DoppelPaymer threat actor group. The incident involved the exfiltration and public dumping of sensitive patient and business files on December 14, 2020. Attackers released proof-of-attack materials containing laboratory test results, diagnostic information, and detailed patient rosters from more than a dozen healthcare facilities on Long Island. The compromised patient records included names, dates of birth, Social Security numbers, Medicare and Medicaid identifiers, admission/discharge dates, gender, marital status, religious affiliation, and insurance details. Over 1,000 patients' protected health information was exposed in these rosters, which appeared to contain historical rather than current data. The attackers also leaked routine business documents unrelated to patient care during the data dump.

Cyber Incident Image

The breach posed significant risks due to the sensitive nature of the exposed information, particularly concerning elderly nursing home patients whose data could facilitate identity theft or social engineering attacks. While the laboratory test results and diagnostic files contained specific medical information, the structured roster files presented greater potential for misuse given their organized presentation of personally identifiable information. Apex Laboratory did not respond to multiple inquiries from media outlets regarding the attack or the validity of the leaked data. No information was available regarding containment measures, system restoration, or patient notification processes. The company's mobile testing services for homebound patients and nursing home facilities remained operational according to available information, though the full operational impact was not disclosed.

Sources
Sources available to members
1 source