Express Scripts data breach may have hit 700,000 victims

Share this article:

Last year's data breach of St. Louis-based Express Scripts may be more serious than initially believed.

In November 2008, the major pharmacy benefit management firm said it received an anonymous letter that included the names, Social Security numbers, birth dates and, in some cases, prescription information of 75 members. The writer or writers threatened to release millions of more records if the business failed to pay an unspecified sum of money.

In the last two months, based on new information from the extortionists, Express Scripts began notifying more than 700,000 victims of their personal information may have been compromised.

After initially notifying only the 75 victims from last year, the company in August was told by the FBI that “…the perpetrator of the earlier action had recently forwarded a letter and data file to a law firm,” according to the company's website.

Maria Palumbo, spokeswoman for Express Scripts, would not elaborate on the contents of the letter.

“The FBI is conducting the investigation that was opened last fall,” she told Thursday. “It is still ongoing.”

The website points out, however, that FBI special agents contacted Express Scripts immediately, and the news was not good.

“The data shows that the extortionist possesses additional member records from the same period of time as those identified in the 2008 extortion attempt,” according to the website. “Express Scripts is in the process of notifying these members.”

According to Palumbo, most of the 700,000 notifications were sent as a result of the August FBI action.

The data thieves still threaten to expose the Social Security numbers, addresses, birth dates and prescription information of millions of patients of the pharmacy benefit management firm unless the company pays an undisclosed sum in extortion money. The company has offered a $1 million reward for information leading to the arrest and conviction of the extortionists.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters


More in News

Email promises free pizza, ensnares victims in Asprox botnet instead

Email promises free pizza, ensnares victims in Asprox ...

Cloudmark came upon an email that offers free pizza, but clicking on the link to get the coupon ends with victims being ensnared in a botnet.

Report: most orgs lacking in response team, policies to address cyber incidents

In its Q3 threat intelligence report, Solutionary learned that 75 percent of organizations it assisted had no response team or policies and procedures to address cyber incidents.

Flash redirect campaign impacts Carnegie Mellon page, leads to Angler EK

Flash redirect campaign impacts Carnegie Mellon page, leads ...

Malwarebytes found that, since early July, thousands of sites had been targeted in the campaign.