Cognizant TriZetto breach exposes health data of 3.4 million patients
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,抓住关键点。 文章讲的是TriZetto Provider Solutions公司发生了数据泄露事件,影响了超过340万人。泄露的信息包括姓名、地址、出生日期、社保号等敏感信息。公司是在2025年10月2日发现可疑活动,但入侵其实早在2024年11月就已经开始了。他们用了外部专家进行调查,并采取措施加强安全,还通知了执法部门。受害者在2026年2月才开始收到通知,并提供了免费的信用监控服务。至于攻击者是谁,目前还不清楚。 接下来,我需要把这些信息浓缩到100字以内。重点包括:公司名称、数据泄露人数、泄露的信息类型、入侵时间、公司的应对措施以及受害者的通知时间。 可能会遗漏一些细节,比如是否有金融信息泄露或者是否有赎金软件参与,但这些可能不是最关键的信息。所以最终的总结应该涵盖主要事件和影响。 </think> TriZetto Provider Solutions遭遇数据泄露,超340万人的敏感信息被暴露,包括姓名、地址、出生日期、社保号等。未经授权的访问始于2024年11月,公司于2025年10月发现异常并展开调查。受害者于2026年2月收到通知,并获得免费信用监控服务。 2026-3-6 20:0:20 Author: www.bleepingcomputer.com(查看原文) 阅读量:3 收藏

Cognizant TriZetto breach exposes health data of 3.4 million patients

TriZetto Provider Solutions, a healthcare IT company that develops software and services used by health insurers and healthcare providers, has suffered a data breach that exposed the sensitive information of over 3.4 million people.

The firm, which has been operating under the Cognizant umbrella since 2014, disclosed that it detected suspicious activity on a web portal on October 2, 2025, and launched an investigation with the help of external cybersecurity experts.

The investigation revealed that unauthorized access began nearly a year before, on November 19, 2024.

During the exposure period, the threat actors accessed records relating to insurance eligibility verification transactions, which are part of the process providers use to confirm a patient’s insurance coverage before treatment.

The types of data that have been exposed vary per individual, and may include one or more of the following:

  • Full names
  • Physical address
  • Date of birth
  • Social Security number
  • Health insurance member number
  • Medicare beneficiary identifier
  • Provider name
  • Health insurer name
  • Demographic, health, and insurance information

Affected providers were alerted on December 9, 2025, but customer notification started in early February 2026. According to a filing Maine’s Attorney General submitted today, the number of exposed individuals is 3,433,965.

TriZetto says that payment card, bank account, or other financial information was not exposed in this incident.

Also, the company is not aware of any cases where cybercriminals have attempted to misuse this information.

TriZetto says it has taken steps to strengthen cybersecurity on its systems and informed law enforcement authorities of the incident.

Notification recipients are offered free 12-month coverage of credit monitoring and identity protection services from Kroll to help mitigate risks arising from compromised data.

BleepingComputer has contacted TriZetto to learn more about the nature of the security breach and why the firm delayed notifications to consumers for several months, but we have not received a response by publication time.

No ransomware groups have taken responsibility for the attack yet, and no data leaks linked to TriZetto have appeared on underground forums.

Cognizant itself was rumored to have suffered a Maze ransomware breach in 2020. In June 2025, Clorox sued the IT firm for gross negligence after it allegedly let Scattered Spider operatives into its network following a social engineering attack in September 2023.

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/security/cognizant-trizetto-breach-exposes-health-data-of-34-million-patients/
如有侵权请联系:admin#unsafe.sh