Aetna Details

    Organization Logo

    Aetna

    Hartford, Connecticut employees • Insurance

    Industry

    Insurance

    Security Incidents

    1

    Aetna Inc. is an American managed health care company that sells traditional and consumer directed health care insurance and related services, such as medical, pharmaceutical, dental, behavioral health, long-term care, and disability plans, primarily through employer-paid insurance and benefit programs, and through Medicare.

    Security Incidents

    Aetna Breach of Jun 2023
    Severity Score
    Moderate

    Type

    Unknown

    Summary

    In June 2023, Aetna was impacted by a cyber incident involving their printing and mailing vendor, OneTouchPoint, who fell victim to a ransomware attack. A total of 326,278 Aetna ACE plan members were notified that their data may have been accessed during this breach. This incident was part of a series of data breaches involving Aetna's business associates, with a previous phishing attack in 2020 exposing the PHI of 484,157 plan members. The ransomware attack on OneTouchPoint was attributed to a Russia-linked ransomware group called Clop, highlighting the sophisticated nature of the threat acto...
    Show more

    Severity

    The breach was severe as Aetna's third-party vendor, Fortra, LLC, was hacked by a Russia-linked ransomware group called Clop, impacting Aetna's benefits administration service NationsBenefits. Additionally, Aetna experienced a security incident due to the use of Progress Software's MOVEit file transfer software by a third party, resulting in unauthorized access to a MOVEit Transfer server.

    Impact

    The breach impacted over 130 organizations, including Aetna, with data possibly accessed during a ransomware attack against their printing and mailing vendor OneTouchPoint. A total of 326,278 Aetna plan members were notified of the breach, highlighting the significant number of individuals affected by the incident.