INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Cognizant TriZetto Exposes Health Data of 3.4 Million Patients
| 2026-03-06 19:50 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
A data breach at TriZetto Provider Solutions, a healthcare IT company under the Cognizant umbrella since 2014, exposed sensitive information of over 3.4 million patients between November 19, 2024 and October 2, 2025. The breach was detected nearly a year after unauthorized access began, with threat actors accessing records relating to insurance eligibility verification transactions. Affected providers were alerted on December 9, 2025, but customer notification started in early February 2026. TriZetto says it has taken steps to strengthen cybersecurity and informed law enforcement authorities of the incident; no ransomware groups have taken responsibility for the attack yet.
Technical Mitigations AI-generated
• User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures.
• Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate.
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered Spider
MazeMaze
Target & Sectors
Global Scope
financefinance
healthhealth
Incident Timeline
February 2026
Threat actors using social engineering tactics gained unauthorized access to Cognizant's network in September 2023.
Click on any entity below to view its context and source!
threat_actor
Scattered Spider
In June 2025,
Clorox sued
the IT firm for gross negligence after it allegedly let Scattered Spider operatives into its network following a social engineering attack in September 2023.
2026/03/06
Threat actors successfully breached TriZetto Provider Solutions, exposing sensitive health data of approximately 3.4 million patients.
Click on any entity below to view its context and source!
infrastructure
3.4
TriZetto Provider Solutions, a healthcare IT company that develops software and services used by health insurers and healthcare providers, has suffered a data breach that exposed the sensitive information of over 3.4 million people.
Tactical Metrics
Metrics
infrastructure
3.4
Software Version
Click for context!
TriZetto Provider Solutions, a healthcare IT company that develops software and services used by health insurers and healthcare providers, has suffered a data breach that exposed the sensitive information of over 3.4 million people.
Intelligence Sources
BleepingComputer
2026-03-06
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T06:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
10x
timeline
Temporal Reference
December 9, 2025
date
7x
organisation
Identified Entity
TriZetto
entity
3x
tactic
Cyber Operation Type
Data Breach
tactic
2x
industry
Targeted Sector
Health
sector
Contextual Telemetry
Context Block
9 METRICS
general metric
Patients
3,400,000
patients
infrastructure
Software Version
3.4
version
malware
Malware Payload
Maze
tool
threat actor
APT Group
Scattered Spider
actor
general metric
Individuals
3,433,965
individuals
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
general metric
Red Report
2,026
red report
general metric
Malicious Samples
1,100,000
malicious samples
general metric
Top Techniques
10
top techniques
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.