Menu
Browse

Cyber Incident Victim: Reproductive Biology Associates

Date:

Apr 2021

Location:

United States of America

Summary

A Georgia-based fertility clinic suffered a ransomware attack compromising sensitive data of approximately 38,000 patients. Attackers encrypted a server containing embryology data and exfiltrated personal and health information, including full names, addresses, Social Security numbers, laboratory results, and details related to human tissue handling. The clinic regained access to encrypted files through a decryptor and received confirmation from the threat actor that stolen data was deleted. An investigation revealed unauthorized system access prior to the encryption event, prompting engagement of an IT services firm to enhance network security. Affected individuals were offered identity theft monitoring services due to potential exposure of highly sensitive identifiers and medical information.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Reproductive Biology Associates (RBA), a Georgia-based fertility clinic providing services including egg donor recruitment and storage through its affiliate MyEggBank, experienced a ransomware attack that compromised sensitive patient data. The clinic first detected the incident on April 16, 2021, when attackers encrypted a file server containing embryology data, rendering it inaccessible. Forensic analysis indicated initial unauthorized system access occurred earlier on April 7, with threat actors breaching a server holding protected health information by April 10. This timeline aligns with typical ransomware attack patterns where adversaries establish network footholds before executing encryption and data exfiltration.

Cyber Incident Image

RBA confirmed on June 7, 2021, that attackers stole personal information affecting approximately 38,000 patients during the intrusion. Compromised data included full names, addresses, Social Security numbers, laboratory results, and sensitive details regarding human tissue handling. The clinic engaged an IT services firm to investigate the attack methodology, assess data exposure, and implement network security enhancements. While RBA did not explicitly acknowledge paying ransom, their breach notification stated they regained access to encrypted files and received assurancess from the threat actor that stolen data was deleted. Affected individuals were offered complimentary identity theft monitoring services and advised to review credit reports for fraudulent activity. The incident exposed patients to potential secondary threats including targeted phishing schemes leveraging fertility treatment details and financial fraud risks stemming from exposed Social Security numbers.

Sources
Sources available to members
1 source