Healthcare provider · Hospital and clinical services · Integrated health system · USA
Catholic healthcare system operating hospitals and clinics.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
OSF HealthCare data was exposed in the 2023 Cl0p MOVEit campaign via its vendor Welltok, which used the vulnerable MOVEit Transfer platform. About 520,000 records were affected, including names, mailing and email addresses, phone numbers, dates of birth, genders, Social Security numbers, and National Provider Identifier (NPI) numbers.
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
520K records analyzed
OSF HealthCare is a US Catholic health system operating hospitals and clinics across Illinois and Michigan.
Integrated healthcare systems collect patient identity, medical records, billing data, insurance information, and clinical interaction data across hospital networks.
SSNs combined with full identity and health-adjacent identifiers create serious identity-fraud and medical-fraud risk for patients.
• Identity theft and synthetic identity construction using government-issued IDs | • SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure | • Medical identity fraud or insurance abuse using health data
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion
A mature extortion group associated in public reporting with TA505 and FIN11-linked ecosystems. Cl0p is known for mass exploitation of managed file transfer products, including the 2023 MOVEit Transfer campaign exploiting CVE-2023-34362.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation