Community Health Systems (CHS) announced a data compromise, wherein attackers used Fortra's GoAnywhere MFT platform's zero-day vulnerability.
Up to 1 million patients were harmed, according to an investigation CHS undertook to see if any of its systems were compromised.
The Company now estimates that up to one million people may have been impacted by this assault. This information was compromised by the Fortran breach.
All affected people whose information was exposed in the data breach will be notified and offered protection services by the company.
Source: https://securityaffairs.com/142242/data-breach/community-health-systems-data-breach.html
TPRM report: https://scoringcyber.rankiteo.com/company/community-health-systems
"id": "com201281023",
"linkid": "community-health-systems",
"type": "Data Leak",
"date": "02/2023",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': '1 million',
'industry': 'Healthcare',
'name': 'Community Health Systems',
'type': 'Healthcare Provider'}],
'attack_vector': 'Zero-day vulnerability',
'data_breach': {'number_of_records_exposed': '1 million',
'type_of_data_compromised': 'Patient information'},
'description': 'Community Health Systems (CHS) announced a data compromise, '
"wherein attackers used Fortra's GoAnywhere MFT platform's "
'zero-day vulnerability. Up to 1 million patients were harmed, '
'according to an investigation CHS undertook to see if any of '
'its systems were compromised. The Company now estimates that '
'up to one million people may have been impacted by this '
'assault. This information was compromised by the Fortran '
'breach. All affected people whose information was exposed in '
'the data breach will be notified and offered protection '
'services by the company.',
'impact': {'data_compromised': ['Patient information']},
'response': {'communication_strategy': 'Notify and offer protection services '
'to affected individuals'},
'title': 'Community Health Systems Data Breach',
'type': 'Data Breach',
'vulnerability_exploited': "Fortra's GoAnywhere MFT platform's zero-day "
'vulnerability'}