Rhode Island Secures $18M Settlement with Deloitte Over 2024 RIBridges Data Breach
Rhode Island Governor Dan McKee announced a $7 million settlement with Deloitte following the 2024 RIBridges data breach, which exposed the personal information of over 700,000 individuals. The agreement also includes an additional $5 million to cover unexpected expenses in 2025, along with $6 million in system enhancements, operational support, and business continuity services provided by Deloitte.
The breach, which prompted the state to shut down the RIBridges social benefit system in December 2024, compromised data of current, former, and even some individuals who had no direct connection to the system. Governor McKee emphasized that the settlement aims to protect taxpayers while ensuring the state has the resources to restore services for residents reliant on critical benefits.
Thomas Verdi, acting director of the Department of Administration, described the agreement as a comprehensive and carefully negotiated resolution, providing both financial compensation and technological improvements to strengthen system security. The state continues to address the fallout of the incident, which disrupted access to essential services for vulnerable populations.
Deloitte Government & Public Services cybersecurity rating report: https://www.rankiteo.com/company/deloitte-government
"id": "DEL1777062709",
"linkid": "deloitte-government",
"type": "Breach",
"date": "12/2024",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '700,000+ individuals (current, '
'former, and some with no direct '
'connection to the system)',
'industry': 'Public Sector/Social Services',
'location': 'Rhode Island, USA',
'name': 'State of Rhode Island',
'size': 'State government',
'type': 'Government'}],
'data_breach': {'number_of_records_exposed': '700,000+',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High (personally identifiable '
'information)',
'type_of_data_compromised': 'Personal information'},
'date_detected': '2024-12',
'description': 'Rhode Island secured an $18 million settlement with Deloitte '
'following a 2024 data breach that exposed the personal '
'information of over 700,000 individuals. The breach led to '
'the shutdown of the RIBridges social benefit system in '
'December 2024.',
'impact': {'data_compromised': 'Personal information of over 700,000 '
'individuals',
'downtime': 'System shutdown in December 2024',
'financial_loss': '$18M settlement (including $7M settlement, $5M '
'for unexpected expenses, and $6M in system '
'enhancements/support)',
'identity_theft_risk': 'High (personal information exposed)',
'operational_impact': 'Disrupted access to essential services for '
'vulnerable populations',
'systems_affected': 'RIBridges social benefit system'},
'post_incident_analysis': {'corrective_actions': 'System enhancements, '
'operational support, and '
'business continuity '
'services provided by '
'Deloitte'},
'references': [{'source': "Rhode Island Governor's Office"}],
'response': {'containment_measures': 'System shutdown',
'remediation_measures': 'Settlement with Deloitte for system '
'enhancements and operational support',
'third_party_assistance': 'Deloitte (settlement and system '
'enhancements)'},
'title': 'RIBridges Data Breach',
'type': 'Data Breach'}