Magnolia Health Corporation suffered a data breach incident after an unknown person impersonated its CEO and obtained an Excel spreadsheet containing the personal information of all active employees.
The compromised information included the employee's name number, address, sex, date of birth, Social Security Number, Salary/Hourly, Salary/Rate, Department, and Job Title.
The health corporation offered all the affected staff free identity theft prevention and mitigation service.
Source: https://blog.itgovernanceusa.com/blog/spoofed-ceo-email-causes-data-breach-at-health-care-provider
TPRM report: https://scoringcyber.rankiteo.com/company/magnolia-health-corporation
"id": "mag11313522",
"linkid": "magnolia-health-corporation",
"type": "Breach",
"date": "02/2016",
"severity": "85",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Healthcare',
'name': 'Magnolia Health Corporation',
'type': 'Organization'}],
'attack_vector': 'Social Engineering',
'data_breach': {'data_exfiltration': True,
'file_types_exposed': 'Excel Spreadsheet',
'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Personal Information'},
'description': 'Magnolia Health Corporation suffered a data breach incident '
'after an unknown person impersonated its CEO and obtained an '
'Excel spreadsheet containing the personal information of all '
'active employees.',
'impact': {'data_compromised': ["Employee's name number",
'Address',
'Sex',
'Date of birth',
'Social Security Number',
'Salary/Hourly',
'Salary/Rate',
'Department',
'Job Title'],
'identity_theft_risk': True},
'initial_access_broker': {'entry_point': 'CEO Impersonation',
'high_value_targets': 'All Active Employees'},
'motivation': 'Data Theft',
'post_incident_analysis': {'corrective_actions': 'Offered free identity theft '
'prevention and mitigation '
'service to affected staff',
'root_causes': 'CEO Impersonation'},
'response': {'remediation_measures': 'Offered free identity theft prevention '
'and mitigation service to affected '
'staff'},
'threat_actor': 'Unknown',
'title': 'Magnolia Health Corporation Data Breach',
'type': 'Data Breach',
'vulnerability_exploited': 'CEO Impersonation'}