Doctors Imaging Group, a Florida-based medical facility, suffered a significant data breach last month that exposed the personal and medical information of 172,000 patients. The breach contributed to Florida’s rising scam losses, where residents lost over $118 million in 2023 nearly double the previous year’s total with 5,500 victims reporting an average loss of $22,000 each. The incident aligns with a broader trend where stolen patient data, combined with AI-driven deepfake scams, enables fraudsters to execute highly convincing financial fraud, particularly through cryptocurrency payments (which accounted for $94 million in losses statewide, with individual losses averaging $94,000). The exposed data likely included sensitive health records, increasing risks of identity theft, blackmail, or targeted phishing attacks. Experts warn that such breaches not only harm individuals financially but also erode trust in healthcare providers, amplifying reputational and operational damages. The breach underscores the escalating intersection of cybercrime, AI exploitation, and healthcare vulnerabilities in Florida’s digital landscape.
TPRM report: https://www.rankiteo.com/company/doctors-imaging-group
"id": "doc4432344110425",
"linkid": "doctors-imaging-group",
"type": "Breach",
"date": "6/2023",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '5,500',
'location': 'Florida, USA',
'name': 'Florida Residents',
'size': '5,500 affected',
'type': 'individuals'},
{'customers_affected': '172,000 patients',
'industry': 'healthcare',
'location': 'Florida, USA',
'name': 'Doctors Imaging Group',
'type': 'healthcare provider'}],
'attack_vector': ['phishing',
'AI-generated deepfakes',
'stolen personal data',
'cryptocurrency extortion'],
'customer_advisories': ['Do not send money without verification, especially '
'via cryptocurrency.',
'Contact banks/exchanges immediately if scammed.',
'Check credit reports for signs of identity theft.'],
'data_breach': {'data_exfiltration': 'yes (sold on dark web)',
'number_of_records_exposed': '172,000 (Doctors Imaging '
'Group); total unknown for all '
'breaches',
'personally_identifiable_information': 'yes (names, contact '
'details, possibly '
'financial/health '
'data)',
'sensitivity_of_data': 'high (PII, healthcare records)',
'type_of_data_compromised': ['personal identifiable '
'information (PII)',
'healthcare data (Doctors '
'Imaging Group)']},
'description': 'Florida residents lost over $118 million to data breach scams '
"in the past year, nearly double the previous year's losses. "
'The scams were exacerbated by the use of AI, deepfakes, and '
'cryptocurrency demands. About 5,500 residents were affected, '
'with an average loss of $22,000 each. Cryptocurrency-related '
'scams accounted for $94 million of the total losses, with an '
'average loss of $94,000 per victim. The Doctors Imaging Group '
'breach exposed data for 172,000 patients, contributing to the '
'rise in fraud.',
'impact': {'brand_reputation_impact': 'high (eroded trust in local '
'institutions and digital transactions)',
'customer_complaints': '5,500 affected residents',
'data_compromised': 'personal data (e.g., Doctors Imaging Group: '
'172,000 patient records)',
'financial_loss': '$118 million (total); $94 million via '
'cryptocurrency',
'identity_theft_risk': 'high (stolen data used for personalized '
'scams)',
'payment_information_risk': 'high (cryptocurrency transactions '
'irreversible)'},
'initial_access_broker': {'data_sold_on_dark_web': 'yes (stolen PII used in '
'scams)',
'entry_point': ['dark web data markets',
'phishing emails',
'compromised third-party vendors '
'(e.g., healthcare providers)'],
'high_value_targets': ['individuals with high net '
'worth',
'elderly populations',
'cryptocurrency holders']},
'investigation_status': 'ongoing (FBI and local authorities investigating)',
'lessons_learned': ['AI and deepfakes amplify the effectiveness of scams by '
'creating highly personalized fraud.',
'Cryptocurrency transactions are irreversible and '
'preferred by scammers for high-value extortion.',
'Stolen data from breaches (e.g., healthcare) fuels '
'secondary scams targeting individuals.',
'Public awareness and rapid reporting (e.g., to IC3.gov) '
'are critical to mitigating losses.'],
'motivation': 'financial gain',
'post_incident_analysis': {'corrective_actions': ['State-wide cybersecurity '
'awareness campaigns.',
'Stricter enforcement of '
'data protection laws '
'(e.g., HIPAA).',
'Collaboration between law '
'enforcement and forensic '
'firms (e.g., CNC '
'Intelligence).',
'Development of AI tools to '
'detect deepfake scams.'],
'root_causes': ['Lack of public awareness about '
'AI-driven scams.',
'Inadequate protection of PII by '
'organizations (e.g., Doctors '
'Imaging Group).',
'Irreversible nature of '
'cryptocurrency transactions '
'enabling high-value fraud.',
'Delayed reporting of scams '
'reducing recovery chances.']},
'recommendations': ['Verify all payment requests, especially those involving '
'cryptocurrency, with trusted contacts.',
'Use multi-factor authentication (MFA) to protect '
'accounts holding sensitive data.',
'Report scams immediately to local law enforcement, '
'banks, and IC3.gov.',
'Educate vulnerable populations (e.g., elderly) on '
'recognizing AI-generated scams.',
'Organizations should audit third-party data security '
'practices to prevent breaches like Doctors Imaging '
'Group.'],
'references': [{'source': 'CNC Intelligence (digital forensics firm)'},
{'source': 'FBI Internet Crime Complaint Center (IC3)',
'url': 'https://www.ic3.gov'},
{'source': 'Media report on Florida scams'}],
'regulatory_compliance': {'regulations_violated': ['potential HIPAA '
'violations (Doctors '
'Imaging Group)',
'state data breach '
'notification laws'],
'regulatory_notifications': ['FBI IC3 reports',
'local law '
'enforcement']},
'response': {'communication_strategy': ['media reports',
'expert recommendations (Matthew '
'Stern, CNC Intelligence)'],
'law_enforcement_notified': 'yes (FBI IC3, local police, '
'cybercrime units)',
'recovery_measures': ['forensic tracing of cryptocurrency '
'transactions',
'victim support guidance'],
'remediation_measures': ["public advisories (e.g., 'slow down, "
"verify before sending money')",
'reporting mechanisms (IC3.gov)'],
'third_party_assistance': ['CNC Intelligence (digital forensics)',
'FBI (via IC3 reporting)']},
'stakeholder_advisories': ['Matthew Stern (CNC Intelligence) advises slowing '
'down transactions and verifying requests.',
'FBI recommends reporting to IC3.gov for '
'cross-case analysis.'],
'threat_actor': ['organized cybercriminal networks',
'scammers leveraging dark web data'],
'title': 'Florida Lost $118M to Data Breach Scams Driven by AI and '
'Cryptocurrency',
'type': ['fraud', 'data breach', 'scam', 'social engineering'],
'vulnerability_exploited': ['compromised personal data',
'lack of multi-factor authentication (MFA)',
'human trust in AI-generated content']}