The US Centers for Medicare & Medicaid Services (CMS) has confirmed that personal and health information of more than 3.1 million individuals was compromised following a cyberattack on Wisconsin Physicians Service (WPS), a contractor providing Medicare administrative services. The breach, tied to the MOVEit vulnerability, came to light in July 2024 during an internal review. The incident occurred when hackers exploited a vulnerability in MOVEit Transfer software used by WPS, allowing them to access and steal sensitive data. The breach occurred despite security patches applied in 2023, with a later investigation revealing that the hackers had already infiltrated WPS systems prior to the updates. CMS, a federal agency within the Department of Health and Human Services (HHS), has begun notifying affected individuals, offering them 12 months of free credit monitoring through Experian to mitigate potential identity theft risks. The attack primarily impacted those using Medicare, thou...