Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Data Breach - Millions of UK Healthcare Workers’ Data Exposed in Software Breach
Data Breach Attacks Critical Infrastructure Security Data Protection News & Analysis Security

Millions of UK Healthcare Workers’ Data Exposed in Software Breach

Katrina ThompsonBy Katrina ThompsonApril 24, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Millions of UK Healthcare Workers’ Data Exposed
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Health-related staff management firm Logezy was recently discovered by ethical hacker Jeremiah Fowler to have left nearly 8 million of its records exposed in a database with neither password protection nor encryption.

The files contained both structured and unstructured data, from PDF files of work authorization documents to images of drivers’ licenses.

Logezy is a software company that facilitates employee data management, dealing with such things as compliance and payroll. As such, it frequently ingests sensitive documentation, and the contents of the database ran the gamut: national insurance numbers, electronic signatures, timesheets, photographs of employees, government-issued ID documents, and various certificates.

Fowler noted that while the company claims to serve across all sectors, the specific cross-section of data he came across when investigating pertained solely to healthcare and healthcare workers. As an ethical hacker, Fowler immediately reported the issue to Logezy – “I do not download the data I discover” – and the company removed the exposed database completely from public access shortly thereafter.

Noting that he implies “no wrongdoing by Logezy, or its employees, agents, contractors, affiliates, and/or related entities,” Fowler offered details of his findings, along with recommendations for best practices to prevent such an exposure in the future.

Potential Outstanding Risks

While the exposed database was discovered, reported, and taken offline upon notification, it is unclear if Fowler was the first to discover it. While this won’t be determinable until an internal forensic audit has been performed, the risks of the data being compromised prior to Fowler’s discovery include:

  • Ransomware attacks: While the database is no longer accessible, data exfiltrated from it could be used in ransomware attacks against Logezy’s clients. Healthcare groups face acute pressure to recapture stolen data as it puts the protected health information (PHI) of their patients at risk and carries severe HIPAA compliance penalties. Research by Claroty indicates that the majority of healthcare organizations have paid at least $500k in ransom payments following a cyberattack.
  • Social engineering attacks: It has been cited that nine out of ten phishing attacks employ some form of social engineering. Using personal data artifacts like the ones discovered in the database, attackers can execute phishing attacks, BEC campaigns, and other forms of social engineering on Logezy’s corporate clients and on the individual data owners themselves.
  • Account takeover: As noted by Fowler, “some documents included the names of supervisors or administrators.” Weaponizing this information, such as in spear phishing attacks, could lead to credential theft and account takeover, which could “increase the hypothetical risks of criminals attempting to steal sensitive patient data or access other sensitive internal resources.”

It is also unknown if the database itself was managed by third parties or if Logezy managed it in-house. If it was managed by a supply chain partner, the possibility of compromise is likely as nearly two-thirds of all organizations have been breached by a third party, per a 2024 study by Miratech. More data privacy frameworks like PCI DSS and DORA are placing responsibility for third-party attacks on the primary entity that contracted them, and it is likely that Logezy would be held accountable even if the oversight was made by an external entity.

Database Security Recommendations

Fowler advocated against providers like Logezy “putting all their eggs in one basket” when it comes to storing the sensitive information of their clients. He advised that companies collecting records from multiple business sources “segment these records in separate cloud storage environments to enhance security, prevent unauthorized access, and minimize the impact of potential data breaches.”

While Logezy had each business’s file in separate folders, those folders remained unprotected by either passwords or encryption. Fowler noted the importance of assigning separate access controls to each unique database, implementing structured segmentation, and encrypting the contents inside.

An Educational Experience

As Fowler states, “I do not claim that any internal, customer, or user data was ever at imminent risk.” The hypothetical risks presented in his report represent potential threats and are intended “exclusively for educational purposes.”

The lesson for providers (healthcare or otherwise) storing sensitive client information is clear. Without proper segmentation, access controls, and encryption, valuable customer data is never fully secure.

Katrina Thompson

An ardent believer in personal data privacy and the technology behind it, Katrina Thompson is a freelance writer leaning into encryption, data privacy legislation, and the intersection of information technology and human rights. She has written for Bora, Venafi, Tripwire, and many other sites.

  • Katrina Thompson
    What Are AI SOC Agents? Use Cases, Architecture, and the Leading Vendors
  • Katrina Thompson
    How EM is boosting the career trajectory of VM analysts
  • Katrina Thompson
    The 7 Top AI SOC Platforms to Watch in 2026
  • Katrina Thompson
    The Best Exposure Assessment Platforms for 2026

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

7-Eleven Notifies Franchise Applicants After Breach Exposes Personal Data

May 19, 20262 Mins Read

Canvas cyberattack disrupts universities as ShinyHunters threatens massive data leak

May 12, 20267 Mins Read

Zara Owner Inditex Confirms Customer Data Breach Affecting Nearly 200,000 People

May 11, 20263 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}