Sectors

Healthcare

Documented social engineering incidents targeting the healthcare sector, sourced and fact-checked.


10 Cases
Confirmed

Rite Aid Pharmacy Dumpster Disposal of Patient and Employee Records

TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels, patient records and job applications, leading to a joint FTC/HHS settlement including a $1 million HIPAA payment and a 20-year FTC security-audit order.

Incident 2006Read →
Confirmed

Single Operator Weaponizes Claude Code and GPT-4.1 to Breach Nine Mexican Government Agencies

A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it with OpenAI's GPT-4.1 for mass data triage, using the combination to autonomously breach nine Mexican government bodies plus a financial institution and exfiltrate roughly 150GB (~195 million records) over about seven weeks.

Incident 2025Read →
Confirmed

Main Line Health W-2 Executive-Spoof Phishing Breach

A spoofed email impersonating a company executive tricked a Main Line Health employee into emailing the W-2 and personal data of all ~11,000 staff to criminals.

Incident 2016Read →
Confirmed

Medidata Solutions $4.8M CEO-Fraud Wire Transfer (2014)

Spoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller, tricked finance staff into wiring $4.8M to an overseas account for a bogus acquisition.

Incident 2014Read →
Confirmed

Kaiser Permanente Medical Waste and Patient Records Dumpster-Disposal Settlement

California's Attorney General and six county DAs found more than 10,000 paper patient records and hazardous/medical waste in unsecured, publicly accessible dumpsters at 16 Kaiser Permanente facilities statewide, resulting in a $49 million settlement.

Incident 2023Read →
Confirmed

CVS Caremark Pharmacy Trash Disposal Case (FTC/HHS Settlement)

CVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters; media exposure across a dozen-plus cities led to a $2.25M HHS settlement and a separate FTC consent order in 2009.

Incident 2006Read →
Confirmed

Doorstep Dispensaree: Unsecured Patient Records Found in a Pharmacy's Back Yard Trigger the ICO's First GDPR Fine (2019)

An MHRA search warrant unrelated to data protection stumbled on an estimated ~500,000 (later found to be far fewer) care-home patients' hard-copy prescription and NHS records left rotting in unlocked crates, bin bags and a cardboard box in the open rear yard of a London pharmacy supplier, triggering the ICO's first-ever GDPR fine.

Incident 2018Read →
Confirmed

Anthem health-insurer breach (78.8M records)

A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that quietly stole personal data on 78.8 million people over the next 11 months.

Incident 2014Read →
Confirmed

GTG-2002 "Vibe Hacking": Claude Code Weaponized for Agentic Data Extortion Against 17 Organizations

A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted, financially calibrated ransom notes demanding up to $500,000.

Incident 2025Read →
Confirmed

Alkem Laboratories: Ascend Laboratories Impersonation BEC and Enzene Biosciences Email Compromise

Fraudsters impersonating named Ascend Laboratories executives convinced an Alkem Laboratories treasury manager to wire Rs 51.30 crore to a fake US bank account under a bogus tax-refund pretext; Rs 22.31 crore was never recovered, and a second, separate business-email-compromise hit Alkem's Enzene Biosciences US subsidiary roughly 18 months later.

Incident 2023Read →