Social EngineeringIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
RS Medical
bd_51b00751b6601cd3 · schema v1 · pii pii-v1
Full breach record for RS Medical →RS Medical notified customers in Delaware of a February 2019 incident where an employee's email account was accessed by external actors who sent 10,000 phishing emails. The breach potentially exposed names, addresses, DOBs, SSNs, and diagnosis codes. RS Medical notified HHS and the Delaware AG, implemented security upgrades, and educated staff.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2019/06/RS-Medical-Customer-Breach-Notification-Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 1, 1971
- Raw hash
- 98c2565ad7a96cb28cbbcb40ba4debca86c8f36b964dd1431706780a2028f23a
Reporting entity
- Name
- RS Medicalnorm: rs medical
- Domain
- rsmedical.com
Victim entity
- Name
- RS Medicalnorm: rs medical
- Domain
- rsmedical.com
Incident
- Discovered
- Feb 12, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the US Department of Health and Human ServicesNotified state’s Attorney General
- Initial access
- phishing_link
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.