Mexican healthcare sector faces major data breach, putting over 5 million individuals at risk

Published:

spot_img

Data Leak Exposes Over Five Million Patients in Mexico: Cybernews Discovery

Over five million patients in Mexico are facing a potential risk after a data leak from hospital information systems due to a missing password. The Cybernews research team uncovered a misconfigured Kibana instance on August 26th, which stored a massive amount of patient data, including names, ethnicities, nationalities, religions, blood types, dates of birth, genders, phone numbers, email addresses, Mexican personal identification numbers (CURP), healthcare service charges, hospitals visited, and payment request descriptions.

The leaked database exposed 5.3 million individuals in Mexico, approximately 4% of the country’s population. The open instance was attributed to eCaresoft Inc., a Texas-based software company that operates cloud-based Hospital Information Systems. Although the leak did not include health records, the leaked CURP numbers pose a significant risk as they could be used for identity theft and fraud.

Cybercriminals could exploit this data for various illegal activities, including insurance fraud, unauthorized transactions, and identity theft. The leaked information could also be used for phishing attacks and blackmail schemes. eCaresoft responded by stating that the leaked data was from a test instance with anonymized and randomly generated test data, not real patient information.

This incident highlights the importance of securing sensitive data and the potential risks posed by unintentional data leaks. Companies must prioritize cybersecurity practices to prevent such incidents in the future. Cybernews research has shown that data leaks due to unsecured databases are a common issue, emphasizing the need for proactive measures to safeguard personal information.

spot_img

Related articles

Recent articles

Suno Data Breach Exposes 55.3 Million User Accounts, Raising Concerns Over AI Data Governance

A significant data breach at the AI music generation platform Suno has exposed sensitive information belonging to over 55.3 million user accounts. This breach,...

Stadler Rail Rejects Everest’s $12.3 Million Ransom Demand Following Data Breach

Swiss train manufacturer Stadler Rail has announced it will not pay a $12.3 million ransom demanded by the ransomware group Everest, following a data...

Fake Bahrain Alert App Deploys Advanced Android Surveillance Malware Targeting Gulf Region Users

A sophisticated cyber-espionage campaign has been identified involving a fake Bahrain Alert Android application. This malicious app, masquerading as an official civil defense tool,...

Microsoft patches record 622 vulnerabilities, including two actively exploited zero-days

Microsoft has issued a significant security update, addressing a record 622 vulnerabilities in its products, including two actively exploited zero-day vulnerabilities. This update, part...