AdaptHealth, a major provider of home healthcare equipment, has confirmed a significant data breach following a successful social engineering attack against a third-party contractor. The incident allowed unauthorized actors to gain access to the company's cloud-based systems.
Exploiting the Human Element
According to reports, the attackers used "sweet-talking" or social engineering tactics to manipulate contractor personnel, eventually securing the credentials needed to bypass security protocols. Once inside the cloud environment, the hackers were able to access a variety of sensitive information.
Scope of the Compromise
The stolen data includes critical patient health information and passwords used for insurance billing. While the full scale of the impacted user base has not been explicitly detailed, the exposure of billing credentials raises significant concerns regarding potential fraudulent activity and identity theft. AdaptHealth is currently investigating the depth of the breach and working to secure its infrastructure against further unauthorized access.


