Osseg Obra Social de Seguros

Osseg Obra Social de Seguros

Obra Social Seguros (OSSEG), an organization that provides health insurance services for the social work union was targeted by the Vice Society.

Vice Society also posted the stolen around 15-16 GB of data including folders, history files, scans, and more on the dark web leak site.

Most of the files were embed patient names or individuals’ names and one directory of scanned files appeared to relate to the medical information of members.

OSSEG’s website alerted members to “technical” problems but did not tell them about the attack.

Source: https://www.databreaches.net/four-ransomware-attacks-on-non-u-s-medical-entities-did-anyone-get-notified/

TPRM report: https://scoringcyber.rankiteo.com/company/osseg-obra-social-de-seguros

"id": "oss1474922",
"linkid": "osseg-obra-social-de-seguros",
"type": "Breach",
"date": "06/2022",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Healthcare',
                        'name': 'Obra Social Seguros (OSSEG)',
                        'type': 'Health Insurance Provider'}],
 'data_breach': {'data_exfiltration': True,
                 'file_types_exposed': ['folders', 'history files', 'scans'],
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['patient names',
                                              'individuals’ names',
                                              'medical information']},
 'description': 'Obra Social Seguros (OSSEG), an organization that provides '
                'health insurance services for the social work union, was '
                'targeted by the Vice Society. Vice Society also posted the '
                'stolen around 15-16 GB of data including folders, history '
                'files, scans, and more on the dark web leak site. Most of the '
                'files were embed patient names or individuals’ names and one '
                'directory of scanned files appeared to relate to the medical '
                'information of members. OSSEG’s website alerted members to '
                "'technical' problems but did not tell them about the attack.",
 'impact': {'data_compromised': ['patient names',
                                 'individuals’ names',
                                 'medical information']},
 'initial_access_broker': {'data_sold_on_dark_web': True},
 'response': {'communication_strategy': 'OSSEG’s website alerted members to '
                                        "'technical' problems but did not tell "
                                        'them about the attack.'},
 'threat_actor': 'Vice Society',
 'title': 'Data Breach at Obra Social Seguros (OSSEG)',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.