The California Department of Insurance reported a data breach involving Blue Shield of California on December 22, 2022. The breach occurred when an employee emailed a confidential spreadsheet containing broker Personally Identifiable Information (PII) to a personal email address on October 30, 2022, and again on June 17, 2022. The affected information included names, Social Security Numbers, addresses, phone numbers, and email addresses.
TPRM report: https://www.rankiteo.com/company/blue-shield-of-california
"id": "blu915080425",
"linkid": "blue-shield-of-california",
"type": "Breach",
"date": "6/2022",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Healthcare',
'location': 'California',
'name': 'Blue Shield of California',
'type': 'Health Insurance Provider'}],
'attack_vector': 'Email',
'data_breach': {'file_types_exposed': ['spreadsheet'],
'personally_identifiable_information': ['names',
'Social Security '
'Numbers',
'addresses',
'phone numbers',
'email addresses'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['PII']},
'date_detected': '2022-12-22',
'date_publicly_disclosed': '2022-12-22',
'description': 'The California Department of Insurance reported a data breach '
'involving Blue Shield of California on December 22, 2022. The '
'breach occurred when an employee emailed a confidential '
'spreadsheet containing broker Personally Identifiable '
'Information (PII) to a personal email address on October 30, '
'2022, and again on June 17, 2022. The affected information '
'included names, Social Security Numbers, addresses, phone '
'numbers, and email addresses.',
'impact': {'data_compromised': ['names',
'Social Security Numbers',
'addresses',
'phone numbers',
'email addresses']},
'references': [{'date_accessed': '2022-12-22',
'source': 'California Department of Insurance'}],
'threat_actor': 'Internal Employee',
'title': 'Blue Shield of California Data Breach',
'type': 'Data Breach',
'vulnerability_exploited': 'Human Error'}