CSIDB logo
Incident

Kent County Community Mental Health Authority

Incident posture

Attack window
Oct 2018
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-27 00:00

Linked entities

Victim
Kent County Community Mental Health Authority
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A phishing attack compromised three staff email accounts at Kent County Community Mental Health Authority, potentially exposing protected health information of 2,284 patients. The attackers accessed encrypted accounts through deceptive emails impersonating a trusted source, leading to potential disclosure of names, addresses, Social Security Numbers (limited to 20 individuals), government IDs, demographic details, and provider or family information. While no evidence confirmed actual data access or financial exposure, the organization conducted an internal investigation, implemented password resets, and enhanced anti-phishing safeguards. Affected individuals were offered complimentary identity protection services despite the assessment that identity theft risks were unlikely based on the nature of the exposed data.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On October 28, 2018, Kent County Community Mental Health Authority, operating as Network180 in Michigan, received a series of well-disguised phishing emails impersonating a trusted source. Between November 2 and November 13, 2018, the organization determined that three staff members had fallen victim to the scheme, resulting in unauthorized access to their encrypted email accounts. Network180 initiated an internal investigation led by its HIPAA Privacy Officer, HIPAA Security Officer, IT Department, and legal counsel to assess the scope and impact. The breach exposed protected health information of 2,284 patients, though investigators could not confirm whether attackers actually viewed or accessed the compromised data. Exposed information categories included names, addresses, dates of birth, Medicaid/Medicare ID numbers, internal client identifiers, and in 20 cases, Social Security Numbers. Educational affiliations, provider names, racial/ethnic information, and relative names were also potentially compromised.

Network180 concluded the breach was not preventable despite existing safeguards but implemented remedial measures including mass password resets across email accounts and verification that no additional accounts were compromised. The organization emphasized no financial information was exposed and stated no evidence suggested elevated identity theft risk for affected individuals. As a precautionary measure, Network180 offered one year of complimentary identity protection services through Experian to impacted clients. Notification of the incident was publicly posted on their website, accompanied by customer service contact options for concerned individuals. The investigation determined the phishing attack specifically targeted encrypted email accounts rather than broader network systems, with containment efforts focused on securing email access points and enhancing anti-phishing defenses.

Sources

Sources available to members: 1 source.

CSIDB