Harley Medical Group, a UK-based plastic surgery clinic, has written to customers warning them hackers broke into company servers and accessed their data, in a breach that could affect as many as 480,000 people.
The attackers then tried to blackmail Harley into handing over money to recover the data, according to the letter sent to customers.
Harley, which has 21 clinics across the UK, took down the website so it could issue fixes that would prevent any issues. Police and the Information Commissioner’s Office (ICO) have been informed of the breach.
“We acted immediately when we became aware that an individual had deliberately bypassed our website security, gaining access to contact information from initial inquiries, in an attempt to extort money from the company,” Harley’s chairman Peter Boddy said in the letter.
“I am sorry that the contact information that you provided in your initial enquiry via our website has been accessed in this way.”
Graham Cluley, writing for the Hot for Security blog, was concerned about the potential for further extortion from patients.
“Such information could be used not just to embarrass an individual, but also – potentially – to extort money from them. Furthermore, the private information could be sold to tabloid newspapers or entertainment websites which are scrabbling for some showbiz tittle tattle to fill their pages,” Cluley said.
Love IT security? Try our quiz!
Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector
Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…
Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…
Judge Kaplan praises former FTX CTO Gary Wang for his co-operation against Sam Bankman-Fried during…
Explore the future of work with the Silicon In Focus Podcast. Discover how AI is…
Executive hits out at the DoJ's “staggering proposal” to force Google to sell off its…