Deloitte
Healthcare
Rhode Island's social services and health data breach exposes personal details o...
On **December 13, 2024**, the state of **Rhode Island** was struck by a significant **cybersecurity breach** affecting its social services and health insurance systems. The breach compromised the personal data of potentially **hundreds of thousands of residents** who used the state's online portal, **RIBridges**, to apply for various assistance programs. This attack, attributed to an **international cybercriminal group**, has raised concerns about the safety of government systems handling sensitive personal information.
In this article, we will provide a detailed examination of the breach, its impact, and the ongoing efforts to mitigate the damage, offering insights into the breach's technical aspects, response measures, and the security lessons it underscores.
Rhode Island’s **RIBridges system**, which facilitates access to various public assistance programs, was recently subjected to a **cyberattack** by an international hacker group. The breach led to the compromise of personal data, including **Social Security numbers**, **banking information**, and other sensitive details, putting the state’s residents at significant risk. This attack is a stark reminder of the vulnerabilities present in government-run digital platforms and the escalating threats posed by cybercriminals.
### About the Breach
The breach was first discovered on **December 5, 2024**, when **Deloitte**, the vendor operating the RIBridges system, alerted the state of a potential security threat. However, it wasn’t until **December 13, 2024**, that the breach was confirmed, with Deloitte identifying malicious code within the system and the likelihood that **personally identifiable information (PII)** had been stolen.
---
## What Happened?
On **December 13, 2024**, **Governor Dan McKee** confirmed that the cyberattack, conducted by an international cybercriminal group, had compromised the RIBridges portal. The hackers gained unauthorized access to sensitive data, including **Social Security numbers**, **banking information**, and other **personally identifiable information** (PII) stored within the system.
**RIBridges** is a crucial system used by Rhode Island residents to apply for and manage a variety of government assistance programs, including Medicaid, food stamps, and child care support. The breach raised alarm bells as it impacted potentially hundreds of thousands of individuals who had applied for or received these benefits since **2016**.
The cyberattack was part of a growing trend where cybercriminal groups target governmental systems to steal sensitive data and demand a ransom. The attackers reportedly threatened to release the stolen data unless they received a payment.
---
## Programs Affected
The following programs, which are managed through the **RIBridges system**, were directly impacted by the breach:
- **Medicaid** – Health insurance coverage for low-income individuals and families.
- **SNAP (Supplemental Nutrition Assistance Program)** – Food assistance for low-income families.
- **TANF (Temporary Assistance for Needy Families)** – Financial aid for families in need.
- **CCAP (Child Care Assistance Program)** – Financial assistance for child care.
- **Health Coverage via HealthSource RI** – Insurance coverage purchased through the state’s marketplace.
- **Rhode Island Works (RIW)** – Cash assistance for low-income residents.
- **Long-Term Services and Supports (LTSS)** – Support for individuals with disabilities.
- **General Public Assistance (GPA)** – Aid for low-income Rhode Islanders.
Anyone who has interacted with these services since 2016 could be at risk of having their personal information exposed.
---
## Details of the Data Breach
The breach involved **malicious code** that allowed unauthorized access to sensitive files, which were likely downloaded by the attackers. The data compromised in the breach includes:
- **Full names**
- **Social Security numbers**
- **Addresses**
- **Dates of birth**
- **Bank account numbers and other financial data**
At this stage, the exact scope of the breach is still being assessed, but the compromised data is of high concern due to the presence of **financial information** and **identifiable personal details**.
---
## How the Attack Was Detected
The breach was first detected by **Deloitte**, the vendor operating the RIBridges system, on **December 5, 2024**. Initial reports indicated a potential threat, but it was unclear whether any sensitive information had been exposed.
- **December 5, 2024**: Deloitte notified the state of a possible breach.
- **December 10, 2024**: Deloitte confirmed the breach after hackers sent screenshots of the stolen files.
- **December 11, 2024**: Deloitte identified that the compromised files contained personal identifiable information (PII).
- **December 13, 2024**: The breach was confirmed, and the system was taken offline to prevent further damage.
---
## Impact on Residents
The breach has potentially affected **hundreds of thousands of residents** who have applied for or received benefits through the RIBridges system. While the investigation is ongoing, the following individuals are most likely impacted:
- **Individuals who have applied for or received benefits through Medicaid, SNAP, TANF, or other programs since 2016.**
- **Those who have used HealthSource RI to purchase health insurance.**
The stolen data may include highly sensitive personal information, including **Social Security numbers** and **banking information**, which can lead to identity theft and financial fraud if misused.
---
## State's Response to the Breach
The state of Rhode Island, along with its vendor **Deloitte**, has taken swift action to address the breach. The **RIBridges system** has been taken offline to prevent further unauthorized access. The following measures are being implemented:
1. **Investigation and Remediation**: Deloitte and state authorities are working together to assess the full scope of the breach and secure the system.
2. **Notification to Affected Individuals**: All impacted individuals will receive a **notification letter** offering free credit monitoring services.
3. **Dedicated Call Center**: A call center has been set up to assist affected residents and guide them on the next steps.
4. **Law Enforcement Involvement**: The **Rhode Island State Police** and **federal law enforcement** agencies are involved in the investigation.
---
## Preventive Actions for Affected Individuals
Residents whose data has been compromised should take the following preventive measures:
1. **Freeze Credit**: Consider placing a freeze on your credit with all three major credit bureaus (Experian, Equifax, and TransUnion).
2. **Fraud Alerts**: Place a fraud alert on your credit report to prevent unauthorized use.
3. **Monitor Accounts**: Regularly check your bank and credit card statements for any unusual or unauthorized activity.
4. **Password Updates**: Change passwords on accounts that use the same credentials as the breached services. Use strong, unique passwords.
5. **Credit Monitoring**: Take advantage of the **free credit monitoring** offered by the state to detect fraudulent activity early.