INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cognizant TriZetto Exposes Health Data of 3.4 Million Patients

| 2026-03-06 19:50 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
A data breach at TriZetto Provider Solutions, a healthcare IT company under the Cognizant umbrella since 2014, exposed sensitive information of over 3.4 million patients between November 19, 2024 and October 2, 2025. The breach was detected nearly a year after unauthorized access began, with threat actors accessing records relating to insurance eligibility verification transactions. Affected providers were alerted on December 9, 2025, but customer notification started in early February 2026. TriZetto says it has taken steps to strengthen cybersecurity and informed law enforcement authorities of the incident; no ransomware groups have taken responsibility for the attack yet.
Technical Mitigations AI-generated
• User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures. • Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate. • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered Spider MazeMaze
Target & Sectors
Global Scope financefinance healthhealth
Incident Timeline
‎February 2026
Threat actors using social engineering tactics gained unauthorized access to Cognizant's network in September 2023.
threat_actor Scattered Spider
‎2026/03/06
Threat actors successfully breached TriZetto Provider Solutions, exposing sensitive health data of approximately 3.4 million patients.
infrastructure 3.4
Tactical Metrics
Metrics
infrastructure
​3.4
Software Version
Intelligence Sources