TriWest Healthcare Data Breach Exposes Sensitive TRICARE Beneficiary Information
TriWest Healthcare Alliance, a contractor managing healthcare programs for the U.S. Department of Defense (DoD) and Department of Veterans Affairs (VA), confirmed a data breach affecting approximately 12,000 TRICARE beneficiaries. The incident, discovered on April 16, 2023, resulted from a vishing attack in which a threat actor impersonated IT support to deceive a contact center agent into accessing a malicious website.
The compromised data includes names, DoD Benefits numbers, ZIP codes, and in some cases, Social Security numbers, addresses, and dates of birth. TriWest stated that it contained the breach upon detection and has begun notifying affected individuals. No group has claimed responsibility, and the stolen data has not been identified online.
Separately, TriWest disclosed a credential-stuffing attack between April and September 2023 that exposed data belonging to 6.9 million customers, including sensitive genetic ancestry information though this appears unrelated to the April breach.
In a separate incident, Partnered Health, an Australian healthcare provider, reported a cyberattack on June 23, 2024, compromising patient data across 21 clinics in New South Wales, Victoria, Queensland, Western Australia, and the Australian Capital Territory. The Australian regulator later declined to hold Qantas accountable for a prior data exposure affecting 5.67 million customers.
TriWest Healthcare Alliance cybersecurity rating report: https://www.rankiteo.com/company/triwest-healthcare-alliance
"id": "TRI1784306135",
"linkid": "triwest-healthcare-alliance",
"type": "Breach",
"date": "4/2023",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '12000',
'industry': 'Healthcare',
'location': 'United States',
'name': 'TriWest Healthcare Alliance',
'type': 'Healthcare Contractor'}],
'attack_vector': 'Vishing',
'customer_advisories': 'Notifying affected individuals',
'data_breach': {'number_of_records_exposed': '12000',
'personally_identifiable_information': 'Names, DoD Benefits '
'numbers, ZIP codes, '
'Social Security '
'numbers, addresses, '
'dates of birth',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally Identifiable '
'Information',
'Healthcare Data']},
'date_detected': '2023-04-16',
'description': 'TriWest Healthcare Alliance, a contractor managing healthcare '
'programs for the U.S. Department of Defense (DoD) and '
'Department of Veterans Affairs (VA), confirmed a data breach '
'affecting approximately 12,000 TRICARE beneficiaries. The '
'incident resulted from a vishing attack in which a threat '
'actor impersonated IT support to deceive a contact center '
'agent into accessing a malicious website. The compromised '
'data includes names, DoD Benefits numbers, ZIP codes, and in '
'some cases, Social Security numbers, addresses, and dates of '
'birth.',
'impact': {'data_compromised': 'Names, DoD Benefits numbers, ZIP codes, '
'Social Security numbers, addresses, dates of '
'birth',
'identity_theft_risk': 'High'},
'initial_access_broker': {'data_sold_on_dark_web': 'No evidence found',
'entry_point': 'Contact center agent'},
'investigation_status': 'Ongoing',
'post_incident_analysis': {'root_causes': 'Social engineering (vishing '
'attack)'},
'response': {'communication_strategy': 'Notifying affected individuals',
'containment_measures': 'Contained upon detection',
'incident_response_plan_activated': 'Yes'},
'title': 'TriWest Healthcare Data Breach Exposes Sensitive TRICARE '
'Beneficiary Information',
'type': 'Data Breach',
'vulnerability_exploited': 'Social Engineering'}