ACID detected the attempted sale of personally identifiable information (PII) of hundreds of thousands of patients on the dark net. The information included patient treatment records, details of therapy sessions with psychologists, and X-rays, among others.
The targeted healthcare institutions were immediately alerted and provided with all available data on the attack. In one case, the perpetrator was unable to sell the stolen information and posted chunks of data in Pastebin. ACID detected the posted chunks and informed the relevant institution in real time. It also detected activity aimed to defraud health insurers with fake certificates.
Thanks to ACID’s threat detection services, the institutions were able to mitigate the consequences of the attack, close the security breach, and prevent future attacks. The targeted institution also had time to prepare a PR response before the theft became public knowledge.