ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

City of Philadelphia says May cyber attack compromised residents' health & financial data

The City of Philadelphia said it suffered unauthorised access to its systems between May and July that compromised the sensitive personal information of its residents.In a recent data security incident notice, city officials said that on May 24, the City became aware of “suspicious activity in its email environment” and immediately launched an internal investigation, with assistance from third party cyber security experts, to understand the nature and scope of the incident.“The investigation determined that between May 26, 2023 and July 28, 2023, an unauthorised actor may have gained access to certain City email accounts and certain information contained therein. Also, on August 22, 2023, we became aware that the at-issue email accounts include email accounts that may contain protected health information,” the notice reads.The compromised information includes names, addresses, dates of birth, Social Security Numbers, contact information, medical information, including diagnosis and other treatment related information, and financial information, such as claims information.“Upon learning of this event, we immediately took steps further secure our systems and email environment. As part of our ongoing commitment to information security, we are also reviewing our existing policies and procedures, implementing additional administrative and technical safeguards to further secure information in our care, and providing additional training on how to safeguard information in our email environment,” The City added.The City has notified the U.S. Department of Health and Human Services and other relevant authorities about the data security incident and has urged residents to remain vigilant against potential financial fraud and identity theft attempts.The City of Philadelphia is yet to clarify how threat actors infiltrated its internal network or why it took them almost six months to disclose the data breach that may have affected thousands of residents.Commenting on the City disclosing the data security incident six months after it was detected, Chris Hauk, Consumer Privacy Advocate at Pixel Privacy, said that the delay is disappointing considering that the breached information included sensitive healthcare information.“The breach also appears to include Social Security numbers, along with plenty of other information that could be used to perform identity theft. Victims of the breach will want to keep a close eye on their credit, using a credit monitoring service to alert them to any new accounts open in their name,” he said.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543