Express Scripts data breach may have hit 700,000 victims

Last year's data breach of St. Louis-based Express Scripts may be more serious than initially believed.

In November 2008, the major pharmacy benefit management firm said it received an anonymous letter that included the names, Social Security numbers, birth dates and, in some cases, prescription information of 75 members. The writer or writers threatened to release millions of more records if the business failed to pay an unspecified sum of money.

In the last two months, based on new information from the extortionists, Express Scripts began notifying more than 700,000 victims of their personal information may have been compromised.

After initially notifying only the 75 victims from last year, the company in August was told by the FBI that “…the perpetrator of the earlier action had recently forwarded a letter and data file to a law firm,” according to the company's website.

Maria Palumbo, spokeswoman for Express Scripts, would not elaborate on the contents of the letter.

“The FBI is conducting the investigation that was opened last fall,” she told SCMagazineUS.com Thursday. “It is still ongoing.”

The website points out, however, that FBI special agents contacted Express Scripts immediately, and the news was not good.

“The data shows that the extortionist possesses additional member records from the same period of time as those identified in the 2008 extortion attempt,” according to the website. “Express Scripts is in the process of notifying these members.”

According to Palumbo, most of the 700,000 notifications were sent as a result of the August FBI action.

The data thieves still threaten to expose the Social Security numbers, addresses, birth dates and prescription information of millions of patients of the pharmacy benefit management firm unless the company pays an undisclosed sum in extortion money. The company has offered a $1 million reward for information leading to the arrest and conviction of the extortionists.



More in News

Event ticketing company hacked, at least tens of thousands affected

In the state of Maine alone, more than 22,000 Vendini customers were impacted.

Idaho State University to pay HHS $400K after investigation reveals shoddy security

The U.S. Department of Health and Human Services continues to ramp up its investigations of health care-related entities as a result of breaches.

Critical vulnerablilty discovered in industrial control product

The vulnerability was found in two programmable gateway devices often used by auto, food and manufacturing businesses in the United States. Meanwhile, a new study shows attacks against utility companies are growing.