CSIDB logo
Incident

Western Michigan University Wmed

Incident posture

Attack window
Jun 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-24 00:00

Linked entities

Victim
Western Michigan University Wmed
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A phishing incident at Western Michigan University Homer Stryker MD School of Medicine (WMed) compromised a single employee email account after an individual clicked a malicious link, potentially exposing personal information. The breach affected 2,474 current and former employees along with their healthcare beneficiaries, whose data was accessible through the compromised account. The organization notified impacted individuals of the unauthorized access but did not disclose specific data types involved.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around June 3, 2021, Western Michigan University Homer Stryker M.D. School of Medicine (WMed) experienced a data security incident stemming from a successful phishing attack. An individual within the organization clicked on a malicious link embedded in a phishing email, which subsequently granted unauthorized external access to a single institutional email account. The breach was confirmed by WMed Communications Director Laura Eller during an interview with MLive on June 3, 2021. While the exact timeline of initial compromise wasn't disclosed, the incident prompted WMed to initiate notification procedures shortly after discovery. The compromised email account contained personal information belonging to individuals enrolled in employee healthcare coverage programs.

WMed notified 2,474 affected parties, including current employees, former employees, and their healthcare beneficiaries, about the potential exposure of their personal data. The organization did not publicly specify the exact types of compromised information beyond confirming the exposure of "personal information" through the breached account. No evidence of actual misuse of data was reported at the time of notification. The institution's public communication emphasized the phishing vector as the root cause and indicated the incident was contained to a single email account. Affected individuals received direct notifications, though the specific remediation measures offered (if any) were not detailed in available public statements. The disclosure aligned with standard breach notification protocols for incidents involving healthcare-related personal data.

Sources

Sources available to members: 1 source.

CSIDB