Cyber Incident Victim: Miracle-Ear
Date:
Oct 2017
Location:
United States of America
Summary
A hearing aid company experienced a security breach when an unauthorized intruder compromised an employee email account at its parent organization, potentially exposing excerpts from approximately 554 patient records. The intrusion was detected the following day, though investigators could not confirm whether the attacker accessed or exfiltrated the sensitive health information. The incident impacted administrative systems supporting subsidiary operations, involving personal details from customer accounts.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On October 24, 2017, an unauthorized intruder compromised the email system of Amplifon, the parent company of hearing aid manufacturer Miracle-Ear, based in Plymouth. The breach specifically targeted an employee email account used for administrative and accounting functions supporting Miracle-Ear subsidiaries. The intrusion resulted in the exposure of excerpts from 554 patient records, though the exact nature of the compromised data elements was not publicly disclosed. Amplifon and Miracle-Ear personnel detected the security incident the following morning on October 25, confirming unauthorized access had occurred. Company officials acknowledged the breach in a December 29, 2017 statement but could not confirm whether the attacker had actually viewed or exfiltrated the patient records during their access period. No technical details regarding the intrusion method or duration of unauthorized access were provided in the public disclosure.

The organizations formally notified media outlets of the privacy breach via fax transmission on December 28, 2017, over two months after discovery. This notification timeline suggests internal investigations or forensic reviews occurred between October and December, though no specific containment measures or remediation actions were described in available reports. The incident exclusively affected Amplifon's email infrastructure supporting Miracle-Ear operations, with no indication of broader system compromises across either organization. Public reporting relied solely on the company's statement, which did not address whether affected patients received individual notifications or if regulatory agencies were informed. The StarTribune originally covered the breach, though its full report contains no additional verifiable details beyond the core facts acknowledged in Amplifon's disclosure.
