
American healthcare company Aetna suffered a cyber security incident that involved the Clop ransomware group exploiting a zero-day vulnerability in Fortra’s GoAnywhere MFT software to target one of its vendors.In a recent statement shared with I-Team, an Aetna spokesperson said that the initial data security incident took place at NationsBenefits, a vendor that provides hearing and flex card benefits to some Aetna customers.“Nothing is more central to us than protecting the privacy and security of our members’ information, and we regret any inconvenience this may cause. We are working closely with NationsBenefits as part of their investigation,” the spokesperson said.Aetna is yet to share more details regarding the security incident, including whether any data was compromised from the company’s systems or the number of affected individuals.NationsBenefits announced last month that it suffered a cyber security incident on January 30 that involved the notorious Clop ransomware gang exploiting a zero-day vulnerability in Fortra’s GoAnywhere MFT file transfer application. The company identified the network intrusion on February 7 and promptly contacted Fortra to assist with its investigations.“This incident was first discovered by NationsBenefits on February 7, 2023, at approximately 16:02 UTC, when NationsBenefits’ security monitoring team received an alert regarding a potential security event on the impacted MFT server,” the company explained.Preliminary investigation revealed that the security breach was limited to two MFT servers and the company found no evidence of any other applications or systems within the NationsBenefits environment being compromised.The Clop ransomware group later listed NationsBenefits as a victim on its data leak site and published data stolen from its servers, including NationsBenefits members’ names, addresses, phone numbers, dates of birth, gender, marital status, and insurance details.While the company did not initially comment on the number of affected individuals, a filing with the U.S. Department of Health and Human Services Office for Civil Rights confirms that at least 3,037,303 members have been affected by the data breach.Earlier this year, the notorious Clop ransomware gang exploited a zero-day vulnerability in Fortra’s GoAnywhere MFT file transfer application and victimised at least 130 organisations. The compromised organisations included global industry giants like California-based fintech company Hatch Bank, Australia’s largest gaming and entertainment group, Crown Resorts, luxury brand retailer Saks Fifth Avenue, Japanese tech giant, Hitachi, and many others.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543