North America
The Centers for Medicare and Medicaid Services
The Centers for Medicare and Medicaid Services (CMS) is notifying roughly 103,000 Medicare beneficiaries about a breach tied to unauthorized Medicare.gov account activity.
CMS found that between 2023 and 2025, attackers used valid beneficiary details, such as names, birthdates and Medicare ID numbers, to set up fraudulent online accounts. Once active, those accounts may have exposed provider information, diagnoses and premium data.
Affected accounts have been deactivated, and CMS is notifying impacted individuals by mail.
How it could affect your business
Even secure government platforms remain vulnerable once attackers obtain users' personal information.