![hospital](https://cms.therecord.media/uploads/format_webp/Hospital_bed_169aeaf4c8.jpg?w=3840)Image: Unsplash+ [Jonathan Greig](/author/jonathan-greig)September 6th, 2024 Nearly 1 million Wisconsin Medicare users had information leaked in MOVEit breach=================================================================================Sensitive information belonging to nearly one million Wisconsin residents was breached during the cybercriminal campaign last year that targeted the popular MOVEit file transfer service.The Centers for Medicare -& Medicaid Services (CMS) — the federal agency that manages the Medicare program — and the Wisconsin Physicians Service Insurance Corporation (WPS) said on Friday that they have begun notifying people whose personal information leaked after hackers exploited a vulnerability in the [MOVEit software](https://therecord.media/tag/moveit).According to the release, 946,801 people are being sent notices explaining that their names, Social Security numbers, birthdays, addresses, Medicare account numbers, health insurance information and more were leaked.CMS said it will send victims new Medicare cards in the coming weeks. After getting the new card, those affected were asked to destroy their old ones and inform their providers that they have a new Medicare number.The letters explain that when the original attacks were announced in May 2023, WPS — which is the Wisconsin state contractor that handles Medicare claims and other services — applied the patch for the MOVEit vulnerability and did not find evidence that their systems were accessed by the hackers.But ‘acting on new information,’ in May 2024 WPS conducted another investigation of its MOVEit file transfer system with an unnamed cybersecurity company. They confirmed that before WPS had applied the patch hackers copied files from their system.In July, WPS notified CMS that files containing personal information had been accessed between May 27 and May 31, 2023.The stolen data was collected while WPS was managing Medicare claims and auditing healthcare providers, and the contractor used MOVEit to send the files to CMS.In addition to the letters, CMS is posting a notice on its website for people whose up-to-date contact information they could not find. CMS did not respond to requests for comment about whether that means more people are affected than are listed on the notice.The federal agency said it is still investigating the incident and is working with law enforcement on the effort.They urged victims to sign up for the one year of free credit monitoring services and to generally watch their accounts for fraudulent activity.The campaign against MOVEit is considered by some experts to be one of the largest data breaches ever, with cybersecurity firm Emsisoft [estimating](https://www.emsisoft.com/en/blog/44123/unpacking-the-moveit-breach-statistics-and-analysis/) that 2,773 organizations were impacted by the attacks on MOVEit. The records of nearly 96 million people were exposed and stolen by the group behind the exploitation.The incident caused international outrage as dozens of [government agencies](https://therecord.media/several-us-federal-agencies-affected-by-moveit-breach), [Fortune 500 companies](https://therecord.media/ucla-siemens-energy-latest-moveit-victims) and [more](https://therecord.media/moveit-fallout-continues-nsc-schools) confirmed that troves of data had been stolen by hackers connected to the [Clop ransomware gang](https://therecord.media/tag/clop).The gang is [estimated](https://www.coveware.com/blog/2023/7/21/ransom-monetization-rates-fall-to-record-low-despite-jump-in-average-ransom-payments) to have earned anywhere from $75 million to $100 million just from ransoms during the MOVEit campaign.Last month, the Securities and Exchange Commission [said it would not pursue](https://therecord.media/progress-software-moveit-vulnerability-sec-ends-investigation) enforcement action against the company behind MOVEit — Progress Software — but it is still facing approximately 144 class action lawsuits and several insurance claims, as well as other [state, federal and international investigations](https://therecord.media/progress-facing-lawsuits-sec-action).CMS — which provides health coverage to more than 160 million people through Medicare, Medicaid, the Children’s Health Insurance Program and the Health Insurance Marketplace — [previously said last November](https://therecord.media/more-than-hundreds-thousands-medicare-moveit) that 330,000 Medicare recipients were impacted when the Clop hackers breached the MOVEit system used by a contractor. * [](https://twitter.com/intent/tweet?text=Nearly 1 million Wisconsin Medicare users had information leaked in MOVEit breach%20%20@TheRecord_Media)* [](https://www.linkedin.com/shareArticle?mini=true&url=&title=Nearly 1 million Wisconsin Medicare users had information leaked in MOVEit breach)* [](https://www.facebook.com/sharer/sharer.php?u=&src=sdkpreparse)* [](https://www.reddit.com/submit?url=)* [](https://news.ycombinator.com/submitlink?u=&t=Nearly 1 million Wisconsin Medicare users had information leaked in MOVEit breach) * [News](/)* [Privacy](/news/privacy) Get more insights with the Recorded Future Intelligence Cloud.[Learn more.](https://www.recordedfuture.com/platform?mtm_campaign=ad-unit-record) Tags* [Wisconsin](/tag/wisconsin)* [data breach](/tag/data-breach)* [MOVEit](/tag/moveit)* [medical](/tag/medical) No previous article No new articles ![Jonathan Greig](https://cms.therecord.media/uploads/format_webp/DSC_0283_1_a6f4e4e315.jpg?w=828) [Jonathan Greig](/author/jonathan-greig) is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.[](https://twitter.com/jgreigj)
Related Tags:
NAICS: 52 – Finance And Insurance
NAICS: 518 – Computing Infrastructure Providers
Data Processing
Web Hosting
Related Services
NAICS: 92 – Public Administration
NAICS: 522 – Credit Intermediation And Related Activities
NAICS: 51 – Information
NAICS: 928 – National Security And International Affairs
Clop
Blog: The Record
Associated Indicators: