Advertisement
UK markets closed
  • NIKKEI 225

    39,631.06
    +47.98 (+0.12%)
     
  • HANG SENG

    17,718.61
    +2.11 (+0.01%)
     
  • CRUDE OIL

    83.40
    +1.86 (+2.28%)
     
  • GOLD FUTURES

    2,341.80
    +2.20 (+0.09%)
     
  • DOW

    39,169.52
    +50.66 (+0.13%)
     
  • Bitcoin GBP

    50,029.46
    +879.19 (+1.79%)
     
  • CMC Crypto 200

    1,351.17
    +49.10 (+3.77%)
     
  • NASDAQ Composite

    17,879.30
    +146.70 (+0.83%)
     
  • UK FTSE All Share

    4,451.48
    -0.44 (-0.01%)
     

Blue Shield of California customer data stolen in cyberattack

LYNNWOOD, CA - SEPTEMBER 22, 2023 - People wait in line to register for a free flu vaccine provided by the L.A. Care and Blue Shield of California Promise Health Plans at the Community Resource Center in Lynnwood on September 22, 2023. According to Hector Andrade, with L.A. Care and Blue Shield of California, they were not able to get COVID-19 vaccines for this clinic. They hope to have some by next week for other clinics. They are hosting10 walk-in vaccine clinics at their jointly operated Community Resource Centers across Los Angeles County, providing members and the public with no-cost flu and upcoming COVID-19* vaccines. Visitors also had their blood pressure checked and blood sugar measured. The vaccine clinics will take place from September 22 to October 20, 2023. (Genaro Molina / Los Angeles Times)
People wait in line to register for a free flu vaccine provided by the L.A. Care Health Plan and Blue Shield of California Promise Health Plan in Lynwood in September. (Genaro Molina / Los Angeles Times)

An unknown number of Blue Shield of California members may have had their personal data, including Social Security numbers, birth dates and treatment information, stolen during a cybersecurity breach this spring.

The healthcare insurance provider said the attack targeted the files of one of its contracted vendors, which manages vision benefits for many of Blue Shield’s customers.

“The vendor immediately took the server offline, launched an investigation into the incident, engaged a cybersecurity firm and reported the matter to the FBI,” Blue Shield said in announcing the breach last month. “It was determined that the unauthorized third party exfiltrated information from the server on May 28, 2023, and May 31, 2023.”

ADVERTISEMENT

Oakland-based Blue Shield said it was notified of the breach on Sept. 1 after the vendor discovered a week earlier that an unknown vulnerability in its system had been exploited.

Blue Shield added that there was “no evidence” that its own systems and emails were affected or vulnerable to the attack.

"It was critical for us to take the time to accurately identify potentially impacted individuals and their affected data," a Blue Shield spokesperson said in an email late Friday. "Once that process was completed, we were able to send breach notification letters in mid-November to all members who were potentially impacted."

The spokesperson did not answer a question about how many of Blue Shield's 4.5 million health plan members may have been affected.

The company said it is providing affected members with no-cost credit monitoring with identity restoration services, and has established a dedicated call center to answer questions. It advised members to review their credit reports and account statements and to notify law enforcement of suspicious activity.

This story originally appeared in Los Angeles Times.