Heimdal Security Blog

Millions of Dollars Stolen by Hackers from Healthcare Payment Processors

A new alert has been issued by the Federal Bureau of Investigation (FBI) regarding hacker-conducted cyberattacks, which target healthcare payment processors.

Millions of dollars have been stolen after the threat actors gained access to customer accounts and redirected their payments to bank accounts controlled by them.

Stealing Personal Data

The hackers used the personal details of the victims, which were publicly available, to impersonate them and gain access to their payment information.

The FBI notified that the hackers were employing a variety of methods to gain access to the payment information of the victims, including phishing attacks, spoofing, and modifying the configurations of Exchange Servers.

Over $4.6 Million Stolen

The Bureau declared that these events are neither new nor singular.

From June 2018 to January 2019, cyber criminals targeted and accessed at least 65 healthcare payment processors throughout the United States to replace legitimate customer banking and contact information with accounts controlled by cybercriminals.

Source

According to BleepingComputer, this year alone threat actors have stolen more than $4.6 million from healthcare companies in just three attacks after gaining access to customer accounts and changing payment details.

In February, a major healthcare firm had $3.1 million stolen, after the hacker changed the victims’ direct deposit information to a bank account controlled by the hacker. The same month, another victim lost $700.000 in a similar incident.

In April, another healthcare company, with over 175 medical providers lost $840.000 after a hacker impersonated an employee.

What Is Recommended to Do?

Besides the alert notification, the FBI also gave a list of recommendations that should help reduce the risk of cyber threats. Among the recommendations are included the following:

As always, if you want to keep up to date with everything we post, don’t forget to follow us on LinkedInTwitterFacebookYoutube, and Instagram for more cybersecurity news and topics.