2023 iQor Philippines — HMO vendor GoAnywhere / Cl0p nexus; ~22.5k employee and dependent notices
Data compromised
Employee and dependent membership metadata tied to corporate HMO enrollment per NPC order summaries
Technical writeup
Philippines privacy regulators documented that iQor Philippines' benefits administrator Asalus (Intellicare) suffered Cl0p exploitation of Fortra GoAnywhere MFT, implicating employee and dependent eligibility records iQor processed. Intellicare issued staged statements acknowledging investigation by Mandiant and eventual confirmation of limited theft, while the NPC permitted coordinated notification leveraging the HMO's workflow.
Root cause
Zero-day-style exploitation of GoAnywhere MFT attributed in vendor and government paperwork to Cl0p activity
References
- https://site.intellicare.com.ph/index.php/2023/03/statement-on-reported-cyber-incident/
- https://www.bleepingcomputer.com/news/security/clop-ransomware-claims-it-breached-130-orgs-using-goanywhere-zero-day/
- https://privacy.gov.ph/wp-content/uploads/2024/12/NPC-BN-23-102-07.04.2023_In-re-IQOR-Philippines-Inc_Order.pdf