Altus Lab Exposed 1,317 Records With Personal Health Data in July 2023
HEROIC analysts found a dataset from Altus Lab, a US-based provider of walk-in medical testing services, surfacing on July 11, 2023. The breach involved 1,317 records and exposed a combination of login credentials and personal identifying information, including full names, birthdays, and phone numbers. For a health-adjacent service, that combination of data is accessable to attackers in a way that goes well beyond a simple password reset.
What Attackers Can Do With Medical Testing Account Data
Health service account data is valuable for several reasons. Attackers can use full names, birthdays, and phone numbers to answer security questions on financial accounts. They can combine this data with email addresses to craft convincing phishing messages that reference real health interactions. The bcrypt password hashes in this breach require cracking, but weaker passwords can still be broken using modern GPU rigs, particularly when attackers know the target's birthday and name and can build customized wordlists around them.
What Was Exposed in the Altus Lab Breach
- Email addresses
- Usernames
- First and last names
- Phone numbers
- Birthdays
- Bcrypt password hashes
Why Health Data Breaches Enable Identity Theft More Than Most
Most credential breaches expose a username and a password hash. The Altus Lab breach occured with a richer payload. Birthdays, full names, and phone numbers are the building blocks of identity theft. They are the answers to the questions banks, insurers, and government services use to verify who you are. A person whose health testing account data was leaked may find themselves facing financial fraud, unauthorized medical claims, or social engineering attacks that reference details only their healthcare providers should know. Seperate from the password risk, the PII exposure here is the more lasting threat.
How Database Breaches Work
Database breaches happen when attackers gain access to backend systems through vulnerabilities, misconfigured servers, or stolen credentials. Once inside, exporting user tables is fast and leaves minimal trace if logging is insufficient. Healthcare-adjacent platforms are attractive targets because they combine PII with authentication data in a single table, making each record more valuable than a typical consumer account dump.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across 400 billion records to identify exactly what has been exposed under your email address. If you have ever used Altus Lab for medical testing, run a scan now. The combination of health-linked PII and password hashes in this breach makes early detection partcularly important.
Breach Breakdown
1,317 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds