The Illinois Department of Human Services (IDHS) exposed sensitive data of over 700,000 individuals after internal planning maps containing personal information were inadvertently made publicly accessible online. The incident was caused by misconfigured privacy settings on a mapping website used for resource allocation and decision-making, allowing unauthorized access to data from as early as 2021 until September 2025. The exposed information included addresses, case numbers, demographic details, and medical assistance plan names for Medicaid and Medicare Savings Program recipients, as well as names and case details for Division of Rehabilitation Services (DRS) customers.
Upon discovery of the breach in September 2025, IDHS immediately secured the website and launched an investigation to assess the scope and cause of the exposure. The agency confirmed that approximately 672,616 Medicaid and Medicare Savings Program recipients and 32,401 DRS customers were affected. In response, IDHS updated the privacy settings to restrict access to authorized personnel and began notifying impacted individuals about the incident.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
In response to the incident, IDHS adopted a Secure Map Policy prohibiting customer-identifiable data on public mapping sites and limiting access to customer-related maps by role. The agency also said it found no evidence of data misuse at the time of disclosure.
After securing the maps, IDHS began breach response actions including notifying affected individuals, informing regulators, and providing guidance on fraud alerts and security freezes. Public reporting indicates more than 700,000 people were affected, including about 673,000 Medicaid/Medicare Savings Program recipients and roughly 32,401 rehabilitation services customers.
By September 26, 2025, IDHS had secured the mapping website and fully restricted public access to the exposed maps. The agency later said it could not determine who may have viewed the data because the platform lacked logging.
IDHS identified on September 22, 2025 that internal planning maps containing sensitive customer and health-related information were publicly accessible online. The exposed information affected Medicaid and Medicare Savings Program recipients as well as Division of Rehabilitation Services customers.
In a prior, unrelated incident, phishing attacks on IDHS employee accounts exposed data belonging to more than 1.1 million individuals. Multiple reports cited this December 2024 breach as context for the later map exposure incident.
Incorrect privacy settings on internal planning maps used by the Illinois Department of Human Services caused sensitive data to be exposed online. The earliest reported exposure began in April 2021 for some datasets, while other exposed data began in January 2022.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
7 references tracked. Mallory keeps watching after this page renders.
rescana.com
Open sourcesecurityaffairs.com
Open sourcethecyberthrone.in
Open sourcebankinfosecurity.com
Open sourcenprillinois.org
Open sourcehipaajournal.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.