Post #2625028
2026-01-09 06:29 UTC
@BobLefridge@mastodon.nz Oh whaaaaaaaaaaat. When they first mentioned a compromised account, I'd assumed one of their staff got phished and was wondering how they'd partitioned their roles so that this only gave hackers access to some clinics' data. This explains that and is also absolutely *horrifying*. Multiple heads should be rolling for that kind of architecture.
Replies (3)
-
@BobLefridge@mastodon.nz 2026-01-09 06:30
This is only supposition on my part, but it would explain how easy MMH made the hack. @zeborah@mastodon.nz
-
@chopsstephens@mastodon.nzoss.nz 2026-01-09 06:39
@zeborah@mastodon.nz @BobLefridge@mastodon.nz I suspect it's that only some clinics use the feature, but everyone who uses the feature is impacted.
-
@stephen@microbe.vital.org.nz 2026-01-09 06:46
@zeborah@mastodon.nz @BobLefridge@mastodon.nz one must also assume no monitoring for unusual behaviour. Because systematically exfiltrating docs by guessing document IDs should show up.