Crooks threaten to expose data on millions at benefits firm

Share this article:
Data thieves are threatening to expose the personal details of millions of patients of a major pharmacy benefit management firm unless the company pays up.

St. Louis-based Express Scripts said Thursday that it received an anonymous letter that included the names, Social Security numbers, birth dates and, in some cases, prescription information of 75 members. The writer or writers threatened to release millions of more records if the business failed to pay an unspecified sum of money.

The company, which received the letter in early October, has since notified the FBI and has launched its own investigation after contracting with data security and computer forensic experts. The organization also is notifying affected individuals.

In a statement, Express Scripts did not disclose whether it had suffered a major breach. It said it deploys a number of security solutions that prohibit intruder access to personal information.

"However, as security experts know, no data system is completely invulnerable," George Paz, chairman and CEO, said.

Blackmail threats of this type are unusual. As evidenced by the bust this summer of a major crime syndicate -- responsible for the TJX heist, among others -- data thieves typically prefer to use the information themselves or sell it on the criminal underground.

An FBI spokesperson could not be reached for comment. An Express Scripts spokesman did not immediately respond to a request for comment on Thursday evening EST.
Share this article:

Sign up to our newsletters

More in News

Research shows vulnerabilities go unfixed longer in ASP

Research shows vulnerabilities go unfixed longer in ASP

A new report finds little difference in the number of vulnerabilities among programming languages, but remediation times vary widely.

Bill would restrict Calif. retailers from storing certain payment data

The bill would ban businesses from storing sensitive payment data, for any long than required, even if it is encrypted.

Amplification, reflection DDoS attacks increase 35 percent in Q1 2014

Amplification, reflection DDoS attacks increase 35 percent in ...

The Q1 2014 Global DDoS Attack Report reveals that amplification and reflection distributed denial-of-service attacks are on the rise.