ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

US healthcare management firm NationsBenefits loses 3m members' data to Clop ransomware attack

Florida-based healthcare management company NationsBenefits suffered a significant cyber attack that compromised the sensitive personal information of millions of customers.In a data security incident notice published on April 13, the company said that around January 30, it suffered a cyber security incident that involved the notorious Clop ransomware gang exploiting a zero-day vulnerability in Fortra’s GoAnywhere MFT file transfer application. The FTA software is used by hundreds of companies worldwide, including NationsBenefits.NationsBenefits said it identified the network intrusion on February 7 and promptly contacted Fortra to assist with the investigation of the incident.“This incident was first discovered by NationsBenefits on February 7, 2023, at approximately 16:02 UTC, when NationsBenefits’ security monitoring team received an alert regarding a potential security event on the impacted MFT server,” the company explained.Preliminary investigation revealed that the security breach was limited to two MFT servers and the company found no evidence of any other applications or systems within the NationsBenefits environment being compromised.The Clop ransomware group recently listed NationsBenefits as a victim on its data leak site and has published sensitive personal information associated with the company’s customers. The compromised data includes members’ names, addresses, phone numbers, dates of birth, gender, marital status, and insurance details.While the company did not initially comment on the number of affected individuals, a filing with the U.S. Department of Health and Human Services Office for Civil Rights confirms that at least 3,037,303 members were affected by the data security incident.NationsBenefits has taken GoAnywhere permanently offline and worked with third-party cyber security experts to understand the scope of the data breach. It has also notified law enforcement about the incident and is offering two-year complimentary membership to Experian’s Identity Works service.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543