A rough day at the extortion office and a botched attack on Blossom Health.
An apparent extortionist targeted Blossom Health, a US telehealth and psychiatry platform, by compromising either the platform itself or an individual provider's account and sending what appears to be a ransom demand. The incident came to light after a patient contacted DataBreaches directly to report it.
Why this matters: Psychiatry records are about as sensitive as personal data gets. They can affect jobs, custody cases, insurance, and relationships. When an extortionist gets into a mental health platform, the threat is not just data loss — it is leverage over patients who disclosed things in confidence. Telehealth expanded fast during the pandemic and pulled in a lot of vulnerable people. The security behind many of those platforms did not always keep pace. If your provider is a small telehealth operation, it is worth knowing who actually holds your records and what happens when something like this goes wrong.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.