redalert attacks Bay Bridge Administrators
Bay Bridge Administrators Suffers Ransomware Attack, Exposing Personal Information of Over 250,000 Individuals
Bay Bridge Administrators, a full-service third-party administrator of fully-insured employee benefit plans, has been targeted by a ransomware group known as RedAlert. The attack, which occurred on September 5, 2022, resulted in a network disruption and the unauthorized access and exfiltration of personal information, including names, addresses, birth dates, Social Security numbers, ID and driver's license numbers, and medical and health insurance information.
The company, which represents top-rated insurance companies and has over 90 years of combined experience in the insurance sector, has been notifying the impacted individuals since December 29, 2022. The compromised data was shared with Bay Bridge Administrators either by the individual, the individual's employer, and/or the individual's insurance carrier(s), in connection with enrollment in an employment insurance benefit plan for calendar year 2022.
The ransomware attack led to a class action lawsuit against Bay Bridge Administrators, LLC, alleging that the company's cybersecurity system was deficient and failed to provide prompt notice to victims. The lawsuit also criticized the company for offering a two-year subscription to identity theft protection services, which the plaintiff considered inadequate.
Bay Bridge Administrators has taken steps to secure the network and engaged a cybersecurity firm to conduct an investigation. The company has also offered all individuals whose information was involved 24 months of complimentary services, including credit monitoring, dark web monitoring, a $1 million identity fraud loss reimbursement policy, fully-managed identity theft recovery services, and 90 days of access to a call center.
The attack on Bay Bridge Administrators highlights the importance of robust cybersecurity measures in the insurance sector, where sensitive personal information is often stored and shared. Companies must prioritize data protection and promptly notify individuals in the event of a breach to mitigate potential harm.
Sources
- SecurityWeek: 251k Impacted by Data Breach at Insurance Firm Bay Bridge Administrators
- ClassAction.org: 2022 Data Breach Ignites Class Action Lawsuit Against Bay Bridge Administrators
- SC Magazine: Third-party administrator hack leads to theft of patient data for over 251K
- DOJ - CPB@doj.nh.gov: Notification of Data Security Incident - Bay Bridge Administrators, LLC
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!