Hacker Explores Kitsap Mental Health Services Systems and then Steals Data Next Month

Published
Written by:
Vishwa Pandagle
Vishwa Pandagle
Cybersecurity Staff Editor

Kitsap Mental Health Services (KMHS) suffered a cyber attack from September to October 2024. The hacker downloaded sensitive information during the period they had access to KMHS’s systems.

KMHs offers mental health and other treatments to patients. Upon discovering suspicious activity on their network on October 17 last year, an investigation was launched. They found that an unauthorized user accessed their systems.

Investigations confirmed that hackers first accessed KMHS on September 17, 2024. After a break, they accessed the system data again on October 8, 2024. It is not clear why the hackers got out of the KMHS systems.

However, they maintained persistent access from October 8 to October 19. The compromised data included name of patients, date of birth, Social Security number, driver’s license, and passport number.

The unidentified cybercriminals also downloaded account credentials, including username and password. Moreover, they breached the following medical information:

The hackers also exfiltrated Medicaid numbers, Medicare numbers, health insurance details, and patient account numbers from the Kitsap Mental Health Services systems within days. 

To mitigate the issue, the organization changed the passwords and deployed certain tools to monitor suspicious activity. 

To date, ten individuals from Massachusetts have been impacted by the KMHS breach. However, the full extent of the impact of the cyber attack remains unknown. 

Last year, on December 1,6 KMHS reported the security breach to the U.S. Department of Health and Human Services. In May this year, they disclosed it to the Massachusetts and Vermont Attorney General’s offices.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: