Blood donation firm reveals donor personal data stolen in cyberattack
- OneBlood suffered a cyberattack in July 2024, and has now concluded its investigation
- The analysis has shown OneBlood lost sensitive information on some customers
- Names and Social Security numbers among the details taken
OneBlood, a nonprofit medical organization crucial for the operations of healthcare firms across the Southeastern US, has confirmed it lost sensitive donor information in a ransomware attack.
In July 2024, OneBlood suffered an attack causing an IT system outage and resulted in 250 hospitals activating critical blood shortage protocols.
The move disrupted services across multiple US states, with the organization operating at a ‘significantly reduced capacity’ – meaning whilst OneBlood continued to collect, test, and distribute blood, it had to return to using manual labelling process, which significantly slowed work. The attack also meant surgeries and treatments were impacted across several states as OneBlood looked to get back up to speed.
Names and SSNs
Now, BleepingComputer has published a data breach notification letter that OneBlood allegedly started sending to affected individuals, describing what happened, and what kind of information the attackers compromised.
“On or around July 28, 2024, OneBlood became aware of suspicious activity within its network,” the letter reads. “Our investigation determined that between July 14 to July 29, 2024, certain files and folders were copied from our network without authorization. On or about December 12, 2024, we completed our review and determined that the affected files contained your information.”
The company said the thieves stole people’s names and Social Security numbers (SSN) – but as organizations usually collect a lot more information than this (such as postal addresses, email addresses, phone numbers, demographic data, health information, and more), hackers having stolen “only” names and SSNs could be seen as a silver lining.
Still, even this is enough to engage in phishing, identity theft, and other forms of cybercrime. We don’t know exactly how many people were affected by the incident, but it’s best to invest in some identity theft protection tools.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Even though there is no evidence of the data being abused in the wild, OneBlood is providing affected individuals with free credit monitoring services for a year. Users have until April 9 to activate the service, it added, stressing that they should also keep a close eye on their bank statements for suspicious transactions.
Via BleepingComputer
You might also like
OneBlood suffered a cyberattack in July 2024, and has now concluded its investigation The analysis has shown OneBlood lost sensitive information on some customers Names and Social Security numbers among the details taken OneBlood, a nonprofit medical organization crucial for the operations of healthcare firms across the Southeastern US, has…
Recent Posts
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023