Cyber Incident Victim: Lexington Medical Center
Date:
Feb 2017
Location:
United States of America
Summary
Lexington Medical Center experienced unauthorized access to its employee information database, eConnect/Peoplesoft, compromising personally identifiable information including names, Social Security numbers, and W-2 forms of current and former staff; no patient data was affected. The organization promptly halted further unauthorized access, initiated an investigation with national cybersecurity experts, and notified law enforcement. Affected individuals were offered free credit monitoring, identity theft protection services, and access to a dedicated call center for support, alongside guidance to mitigate risks of fraudulent tax filings and identity theft.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On February 17, 2017, Lexington Medical Center in South Carolina discovered unauthorized access to its employee information database, eConnect/Peoplesoft, during a morning security review. The breach exposed personally identifiable information of current and former employees, including names, Social Security numbers, and W-2 tax forms. Hospital officials confirmed the intrusion affected only the employee database, with no patient data compromised. The organization notified employees of the incident within the same week of discovery, emphasizing prompt transparency despite the ongoing investigation. The attackers specifically targeted payroll and tax documentation through the compromised system, though the exact method of intrusion remained unspecified in public disclosures.

Upon identifying the breach, Lexington Medical Center immediately terminated unauthorized access to the database and initiated a forensic investigation with assistance from national cybersecurity experts. The hospital concurrently engaged federal and state law enforcement agencies to support the inquiry. Affected employees were offered complimentary credit monitoring and identity theft protection services to mitigate potential financial fraud risks. A dedicated call center staffed by identity theft professionals was established to address employee concerns, supplemented by guidance on preventing fraudulent tax filings using stolen data. The incident highlighted vulnerabilities in the hospital's employee data systems, prompting resource allocation toward enhanced safeguards without disclosing specific technical remediation measures. No further unauthorized activity was reported following the containment actions implemented on the discovery date.
