Crooks threaten to expose data on millions at benefits firm

Data thieves are threatening to expose the personal details of millions of patients of a major pharmacy benefit management firm unless the company pays up.

St. Louis-based Express Scripts said Thursday that it received an anonymous letter that included the names, Social Security numbers, birth dates and, in some cases, prescription information of 75 members. The writer or writers threatened to release millions of more records if the business failed to pay an unspecified sum of money.

The company, which received the letter in early October, has since notified the FBI and has launched its own investigation after contracting with data security and computer forensic experts. The organization also is notifying affected individuals.

In a statement, Express Scripts did not disclose whether it had suffered a major breach. It said it deploys a number of security solutions that prohibit intruder access to personal information.

"However, as security experts know, no data system is completely invulnerable," George Paz, chairman and CEO, said.

Blackmail threats of this type are unusual. As evidenced by the bust this summer of a major crime syndicate -- responsible for the TJX heist, among others -- data thieves typically prefer to use the information themselves or sell it on the criminal underground.

An FBI spokesperson could not be reached for comment. An Express Scripts spokesman did not immediately respond to a request for comment on Thursday evening EST.

Sign up to our newsletters

More in News

Bitcoin mining botnet has become one of the most prevalent cyber threats

Fortinet researchers have tracked 100,000 new ZeroAccess trojan infections per week, making the botnet very lucrative to its owners.

House Intelligence Committee OKs amended version of controversial CISPA

House Intelligence Committee OKs amended version of controversial ...

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

Judge rules hospital can ask ISP for help ...

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.