According to reports, threat actors infiltrated DC Health Link’s internal network on March 6 and compromised personal information associated with tens of thousands of health plan members, including US House and Senate members.
A threat actor going by the name “IntelBroker” recently listed DC Health Link Health Benefit Exchange Authority as its victim and claimed to be in possession of personal data belonging to 170,000 individuals.
IntelBroker claimed that the stolen data includes subscriber ID, member ID, policy ID, status, full names, Social Security numbers, dates of birth, gender, relationship, benefit types, plan name, HIOD ID, employers contribution, coverage details, home addresses, citizen status, work emails, and numerous other highly sensitive information.
IntelBroker has offered to sell the stolen data to buyers willing to pay the quoted price and said they will work only with a “Middleman.”
Following IntelBroker’s announcement, the FBI, along with other agencies, launched an investigation into the cyber security incident impacting DC Health Link. The investigation helped the authorities identify two sets of impacted individuals. The first set of individuals are those whose information has been confirmed as stolen and leaked on the dark web. The second set of individuals are those whose data was stored in the affected server, but as of now, there is no evidence that their data has been compromised.
On March 10, the DC Health Benefit Exchange Authority said that 56,415 plan members were affected by the security incident. House of Representatives Chief Administrative Officer Catherine Szpindor
notified the House members and the Senate about the security incident as DC Health Link provides health benefits to them.
The company and law enforcement authorities are yet to confirm the number of affected congressional members. While the company did not clarify how the threat actors infiltrated its network, DC Health Link said that it has identified the source of the security incident and “eliminated” the same.
DC Health Link has started notifying all impacted individuals as well as those suspected to be impacted by the incident about the security incident. They have been provided with three years of identity and credit monitoring for themselves and their enrolled dependents, spouses, and children.