A data breach at an unnamed French hospital uncovered the medical data of 750,000 sufferers after a menace actor gained entry to its digital affected person report system.
A menace actor utilizing the nickname ‘nears’ (beforehand near2tlg) claimed to have attacked a number of healthcare services in France, alleging that they’ve entry to the affected person data of over 1,500,000 folks.
The hacker claims they breached MediBoard by Software program Medical Group, an organization providing Digital Affected person Report (EPR) options throughout Europe.
Softway Medical Group has confirmed that hackers have compromised a MediBoard account. Nonetheless, it famous that this was not the results of a software program vulnerability or misconfiguration on their half, however somewhat by means of the usage of stolen credentials utilized by the hospital.
In a letter despatched to French media and shared with BleepingComputer by LeMagIT’s editor-in-chief, Valéry Rieß-Marchive, Softway Medical Group says the uncovered information was circuitously managed by them, however somewhat hosted by the hospital.
“On November 19, 2024, a cyberattack was detected inside a healthcare facility utilizing the Mediboard software program,” reads the machine-translated electronic mail.
“We need to emphasize that the affected well being information weren’t hosted by Softway Medical Group.”
BleepingComputer contacted Softway Medical Group for clarifications on which account and at what degree was compromised, and a spokesperson shared the next assertion:
“We will verify that our software program shouldn’t be accountable, however somewhat, a privileged account inside the consumer’s infrastructure was compromised by a person who exploited the usual capabilities of the answer,” the Softway Medical Group informed BleepingComputer.
“This speculation has been substantiated. It’s subsequently neither as a result of improper implementation of the software program nor human error.”
Promoting entry to hospitals
This all unfolded after the menace actor started promoting what they claimed was entry to the MediBoard platform for a number of French hospitals, together with Centre Luxembourg, Clinique Alleray-Labrouste, Clinique Jean d’Arc, Clinique Saint-Isabelle, and Hôpital Privé de Thiais.
This entry allegedly would let the client view the hospitals’ delicate healthcare and billing data, affected person data, and the power to schedule and modify appointments or medical data.
To show that they gained entry to the MediBoard accounts, the hacker additionally put the data of 758,912 sufferers from an unnamed French hospital up on the market.
These data allegedly include the next data:
- Full identify
- Date of start
- Gender
- Residence deal with
- Telephone quantity
- E-mail deal with
- Doctor
- Prescriptions
- Well being card historical past
The information was supplied for buy to a few customers, and presently, no consumers have been declared on the sale itemizing.
Even when the info is not offered, there’s at all times a danger of being leaked on-line without cost, making it out there to the broader cybercrime neighborhood.
The kind of information uncovered on this incident raises the chance of phishing, scamming, and social engineering for impacted folks.