@Compl3x1ty
Profile
Organisation tracking is available to eligible accounts.
Profile narrative
@Compl3x1ty is known primarily through its Twitter handle, where it disclosed a cybersecurity incident on February 14, 2015. The disclosure concerned an outdated file‑sharing application used by the Lutheran Health Network for non‑patient documents. According to the tweet, the application had been compromised via SQL injection, exposing 98 usernames, MD5‑hashed passwords, and email addresses. The organization noted that the affected system was legacy and inactive for an extended period. The breach did not involve current patient records, as confirmed by the health network after being notified.
Notification of the Lutheran Health Network was hampered by invalid contact information, which delayed the organization's ability to alert the vendor directly. Once informed, the health network confirmed that the exposed data were historical and unrelated to ongoing patient care. In response, the legacy application was fully decommissioned, with its associated databases and files removed to eliminate any future risk. The incident highlighted the importance of maintaining accessible security‑contact channels for external vulnerability reporters. @Compl3x1ty’s actions underscored the role of public disclosure in prompting remediation of outdated systems.
Incidents
1 incident linked to this organisation.