Express Scripts data breach may have hit 700,000 victims

Share this article:

Last year's data breach of St. Louis-based Express Scripts may be more serious than initially believed.

In November 2008, the major pharmacy benefit management firm said it received an anonymous letter that included the names, Social Security numbers, birth dates and, in some cases, prescription information of 75 members. The writer or writers threatened to release millions of more records if the business failed to pay an unspecified sum of money.

In the last two months, based on new information from the extortionists, Express Scripts began notifying more than 700,000 victims of their personal information may have been compromised.

After initially notifying only the 75 victims from last year, the company in August was told by the FBI that “…the perpetrator of the earlier action had recently forwarded a letter and data file to a law firm,” according to the company's website.

Maria Palumbo, spokeswoman for Express Scripts, would not elaborate on the contents of the letter.

“The FBI is conducting the investigation that was opened last fall,” she told SCMagazineUS.com Thursday. “It is still ongoing.”

The website points out, however, that FBI special agents contacted Express Scripts immediately, and the news was not good.

“The data shows that the extortionist possesses additional member records from the same period of time as those identified in the 2008 extortion attempt,” according to the website. “Express Scripts is in the process of notifying these members.”

According to Palumbo, most of the 700,000 notifications were sent as a result of the August FBI action.

The data thieves still threaten to expose the Social Security numbers, addresses, birth dates and prescription information of millions of patients of the pharmacy benefit management firm unless the company pays an undisclosed sum in extortion money. The company has offered a $1 million reward for information leading to the arrest and conviction of the extortionists.



Share this article:

Sign up to our newsletters

More in News

Brazilian president signs internet 'Bill of Rights' into law

Brazilian president signs internet 'Bill of Rights' into ...

President Dilma Rousseff signed the legislation on Wednesday at the NetMundial conference in Sao Paulo.

Android trojan sends premium SMS messages, targets U.S. users for first time

Android trojan sends premium SMS messages, targets U.S. ...

An SMS trojan for Android, known as FakeInst, has been observed sending premium SMS messages to users all over the world, including, for the first time, the United States.

Report: DDoS up in Q4 2013, vulnerability scanners leveraged to exploit sites

Report: DDoS up in Q4 2013, vulnerability scanners ...

Researchers observed 346 DDoS attacks in the final quarter of 2013 and attackers used Vega and Skipfish vulnerability scanners to exploit web flaws at financial companies.