Crooks threaten to expose data on millions at benefits firm

Share this article:
Data thieves are threatening to expose the personal details of millions of patients of a major pharmacy benefit management firm unless the company pays up.

St. Louis-based Express Scripts said Thursday that it received an anonymous letter that included the names, Social Security numbers, birth dates and, in some cases, prescription information of 75 members. The writer or writers threatened to release millions of more records if the business failed to pay an unspecified sum of money.

The company, which received the letter in early October, has since notified the FBI and has launched its own investigation after contracting with data security and computer forensic experts. The organization also is notifying affected individuals.

In a statement, Express Scripts did not disclose whether it had suffered a major breach. It said it deploys a number of security solutions that prohibit intruder access to personal information.

"However, as security experts know, no data system is completely invulnerable," George Paz, chairman and CEO, said.

Blackmail threats of this type are unusual. As evidenced by the bust this summer of a major crime syndicate -- responsible for the TJX heist, among others -- data thieves typically prefer to use the information themselves or sell it on the criminal underground.

An FBI spokesperson could not be reached for comment. An Express Scripts spokesman did not immediately respond to a request for comment on Thursday evening EST.
Share this article:

Sign up to our newsletters

More in News

Cyber Command tests gov't collaboration in wake of attacks

The two-week exercise, "Cyber Guard 14-1," was completed this month.

Text message spammer settles charges filed by FTC

Text message spammer settles charges filed by FTC

Rishab Verma and his company agreed to settle charges filed by the FTC that Verma sent millions of spam text messages that deceitfully promised free merchandise.

Rhode Island hospital to pay $150K for past data breach

More than 12,000 patients' personal and health information was compromised in a breach at The Women & Infants Hospital of Rhode Island.