TriWest Healthcare Alliance: TriWest Healthcare confirms data breach affecting 12,000 TRICARE beneficiaries

TriWest Healthcare Alliance: TriWest Healthcare confirms data breach affecting 12,000 TRICARE beneficiaries

TriWest Healthcare Data Breach Exposes Sensitive TRICARE Beneficiary Information

TriWest Healthcare Alliance, a contractor managing healthcare programs for the U.S. Department of Defense (DoD) and Department of Veterans Affairs (VA), confirmed a data breach affecting approximately 12,000 TRICARE beneficiaries. The incident, discovered on April 16, 2023, resulted from a vishing attack in which a threat actor impersonated IT support to deceive a contact center agent into accessing a malicious website.

The compromised data includes names, DoD Benefits numbers, ZIP codes, and in some cases, Social Security numbers, addresses, and dates of birth. TriWest stated that it contained the breach upon detection and has begun notifying affected individuals. No group has claimed responsibility, and the stolen data has not been identified online.

Separately, TriWest disclosed a credential-stuffing attack between April and September 2023 that exposed data belonging to 6.9 million customers, including sensitive genetic ancestry information though this appears unrelated to the April breach.

In a separate incident, Partnered Health, an Australian healthcare provider, reported a cyberattack on June 23, 2024, compromising patient data across 21 clinics in New South Wales, Victoria, Queensland, Western Australia, and the Australian Capital Territory. The Australian regulator later declined to hold Qantas accountable for a prior data exposure affecting 5.67 million customers.

Source: https://www.scworld.com/brief/triwest-healthcare-confirms-data-breach-affecting-12000-tricare-beneficiaries

TriWest Healthcare Alliance cybersecurity rating report: https://www.rankiteo.com/company/triwest-healthcare-alliance

"id": "TRI1784306135",
"linkid": "triwest-healthcare-alliance",
"type": "Breach",
"date": "4/2023",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '12000',
                        'industry': 'Healthcare',
                        'location': 'United States',
                        'name': 'TriWest Healthcare Alliance',
                        'type': 'Healthcare Contractor'}],
 'attack_vector': 'Vishing',
 'customer_advisories': 'Notifying affected individuals',
 'data_breach': {'number_of_records_exposed': '12000',
                 'personally_identifiable_information': 'Names, DoD Benefits '
                                                        'numbers, ZIP codes, '
                                                        'Social Security '
                                                        'numbers, addresses, '
                                                        'dates of birth',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personally Identifiable '
                                              'Information',
                                              'Healthcare Data']},
 'date_detected': '2023-04-16',
 'description': 'TriWest Healthcare Alliance, a contractor managing healthcare '
                'programs for the U.S. Department of Defense (DoD) and '
                'Department of Veterans Affairs (VA), confirmed a data breach '
                'affecting approximately 12,000 TRICARE beneficiaries. The '
                'incident resulted from a vishing attack in which a threat '
                'actor impersonated IT support to deceive a contact center '
                'agent into accessing a malicious website. The compromised '
                'data includes names, DoD Benefits numbers, ZIP codes, and in '
                'some cases, Social Security numbers, addresses, and dates of '
                'birth.',
 'impact': {'data_compromised': 'Names, DoD Benefits numbers, ZIP codes, '
                                'Social Security numbers, addresses, dates of '
                                'birth',
            'identity_theft_risk': 'High'},
 'initial_access_broker': {'data_sold_on_dark_web': 'No evidence found',
                           'entry_point': 'Contact center agent'},
 'investigation_status': 'Ongoing',
 'post_incident_analysis': {'root_causes': 'Social engineering (vishing '
                                           'attack)'},
 'response': {'communication_strategy': 'Notifying affected individuals',
              'containment_measures': 'Contained upon detection',
              'incident_response_plan_activated': 'Yes'},
 'title': 'TriWest Healthcare Data Breach Exposes Sensitive TRICARE '
          'Beneficiary Information',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Social Engineering'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.