Menu
Browse

Cyber Incident Victim: Illinois Department of Human Services

Date:

2025

Location:

United States of America

Summary

A data breach at the Illinois Department of Human Services exposed sensitive information of approximately 700,000 individuals through a publicly accessible mapping website. The incident compromised personal details of 32,000 Division of Rehabilitation Services customers, including names, addresses, case numbers, and referral sources, while roughly 672,000 Medicaid and Medicare Savings Program recipients had addresses, case numbers, demographic data, and medical assistance plans exposed—though names were not included in the latter group. The agency confirmed the information was inadvertently available for several years, but it remains unclear whether unauthorized parties accessed the data during that period.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 0 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

The Illinois Department of Human Services (IDHS) disclosed a data breach impacting approximately 700,000 individuals, stemming from a publicly accessible mapping website. The exposure occurred between 2021/2022 and 2025, though the exact discovery timeline and remediation actions were not detailed in public reports. The breach affected two distinct groups: 32,000 Division of Rehabilitation Services (DRS) customers and approximately 672,000 Medicaid and Medicare Savings Program recipients. For DRS customers, compromised data included names, addresses, case numbers, case status details, referral source information, and region-specific data. Medicaid/Medicare recipients had addresses, case numbers, demographic information, and medical assistance plan details exposed, though their names were not included in the leaked dataset. IDHS did not confirm whether unauthorized parties accessed the information during the exposure window.

Cyber Incident Image

The incident represented a significant exposure of sensitive health and social service data, with potential implications for identity theft and fraud given the combination of personal identifiers and case-specific details. For DRS customers, the inclusion of names alongside case status and referral information created risks of targeted social engineering or discrimination. Medicaid/Medicare recipients faced exposure of medical assistance enrollment details tied to addresses and demographic profiles, potentially revealing health program participation without direct name linkage. No technical details regarding the mapping platform's architecture or the mechanism enabling public access were disclosed. IDHS provided no information about containment procedures, forensic investigations, or post-breach notifications beyond the initial disclosure acknowledging the incident's scope and duration.

Sources
Sources available to members
1 source