Published December 17, 2024. Updated September 29, 2026 with the state’s investigation findings and the Deloitte settlements.
The RIBridges breach exposed the personal information of 644,401 people who applied for Rhode Island benefits. It started with one stolen username and password on a vendor’s network. The attackers were inside for almost five months, and the state’s own investigation found that the security tools raised alarms nobody acted on.
No Triton client received a RIBridges letter, but many of their own customers and contractors did.
What happened in the RIBridges data breach?
RIBridges is the system Rhode Island uses to enroll residents in Medicaid, SNAP, RI Works, child care assistance, HealthSource RI and other programs. Deloitte built and ran it for the state.
The state’s forensic firm, CrowdStrike, traced the attack from start to finish (investigation summary):
- July 2, 2024: the attacker first logged in, through a non-production VPN, with a non-state, non-privileged account.
- November 11 to 28, 2024: the attacker copied files out of the system.
- December 4, 2024: the Brain Cipher group posted about the attack on its leak site.
- December 5, 2024: Deloitte told the state.
- December 13, 2024: Deloitte confirmed malicious code was present. The state ordered the system shut down and told the public (state alert page).
- December 30, 2024: the stolen data was published on the dark web, about 576 GB of it (Rhode Island Current).
- January 2025: the state mailed letters and offered five years of Experian credit monitoring, paid for by Deloitte (Governor’s office).
- May 15, 2025: the state released CrowdStrike’s findings and confirmed 644,401 people were affected (Governor’s office).
The exposed data included names, addresses, dates of birth, Social Security numbers, banking information, phone numbers and health information. CrowdStrike found no evidence that ransomware was ever run. This was data theft and extortion, not locked computers.
How did the attackers get into RIBridges?
The attackers logged in with a valid username and password on a VPN that led into a non-production part of the system. CrowdStrike could not determine how the credentials were stolen or whether multifactor authentication was bypassed. Deloitte told investigators that MFA was in place for production accounts, but the MFA logs had not been kept.
A test or “non-production” environment that connects to live systems is a front door. Once inside, the attacker installed remote management tools and set up a reverse proxy on July 12 to keep access. Every vendor account deserves the same controls as your own staff: its own login, MFA, logging and an expiry date.
Almost every new client Triton takes on has at least one back door a vendor left behind: the copier company, the HVAC contractor, the phone vendor or a previous IT provider. At one recent client, a fleet of 30 printers and scanners all shared a single username and password, and that account had been added to Domain Admins for ease of use. We removed the administrator rights from every device and locked the credentials down.
Why did hundreds of security alerts go unanswered?
The security tools worked. On September 10, 2024, the firewall blocked a connection to an outside cloud storage service. Between November 11 and 28, the monitoring tools generated 397 “Large Outbound Transfer” alerts while the data was leaving. None of them stopped the theft.
State IT officials said it directly: “The technology did its job, but there are people and processes that have to follow up on what the technology triggers” (Rhode Island Current).
This has happened before. In 2013, attackers entered Target’s network with credentials stolen from an HVAC contractor, Fazio Mechanical Services, and took 40 million card numbers. The U.S. Senate Commerce Committee found that Target “appears to have failed to respond to multiple automated warnings from the company’s anti-intrusion software.”
Almost every business we take over has alarms and notifications that nobody acts on. Reading security alerts is not an office manager’s job, and many IT providers react only to what lands directly in front of them. Triton runs its own SIEM (security information and event management) and monitoring so warnings are reviewed and patches are applied on schedule.
An alert that nobody reads protects nothing. Monitoring means a person sees the alert, understands it and acts on it, day or night.
Who is responsible when a vendor is breached?
The organization that owns the data carries the obligation to protect it, even when a vendor runs the system. Rhode Island notified the affected residents. Deloitte paid for the credit monitoring and, in April 2026, agreed to pay the state an additional $7 million, bringing its direct payments to $12 million plus $6 million in services, without admitting liability (Governor’s office). Separately, Deloitte settled a class action by affected residents for $6.3 million (Rhode Island Current).
Businesses carry the same responsibility in writing. Massachusetts 201 CMR 17.03(2)(f) requires “taking reasonable steps to select and retain third-party service providers that are capable of maintaining appropriate security measures” and requiring them by contract to maintain those measures. The FTC Safeguards Rule, 16 CFR 314.4(f) adds “periodically assessing your service providers based on the risk they present.”
After the breach, the state reviewed how long its vendor contracts require security logs to be kept, because CrowdStrike never received the firewall or MFA logs. Your vendor contracts should say who keeps which logs, for how long, and how fast a vendor must tell you about an incident.
Is multifactor authentication enough?
Multifactor authentication is required, and it is not enough on its own. A Microsoft study of real attack data found MFA reduced the risk of account compromise by 98.56% even when the password had already leaked. That makes MFA the single most effective control for stolen credentials.
RIBridges shows what else it needs around it:
- Logs kept long enough to investigate.
- Conditional access that blocks logins from unexpected places or devices.
- Phishing-resistant methods where possible.
- Alerts on unusual VPN logins, and a person who responds to them.
What should a business do in the first days after a breach?
Contain it first. Rhode Island shut RIBridges down the day malicious code was confirmed. That cost the state a working system for weeks, and it stopped the attacker.
- Cut off the access path: disable the compromised accounts, VPN profiles and remote tools.
- Preserve the evidence, including firewall, VPN, MFA and endpoint logs, before anything is wiped or overwritten.
- Bring in incident response help and your cyber insurance carrier early.
- Work out whose information was exposed and what the notification laws require. Massachusetts and Rhode Island both have specific notice rules.
- Tell affected people plainly what happened and what you are offering them.
The FTC Safeguards Rule requires covered businesses to “establish a written incident response plan designed to promptly respond to, and recover from, any security event.” Writing it before you need it is the difference between a controlled response and a scramble.
What does RIBridges mean for businesses in Rhode Island and Massachusetts?
The same pattern reaches businesses of every size: a trusted outside company with remote access, a stolen password and alerts nobody answers. Your IT provider, accounting software vendor, payroll company, phone vendor and building systems contractor may all have a way in.
When Triton takes on a new client, we sweep the whole environment, from the firewall and network to email and user accounts, to see who can log in and whether that access is still needed. We ask the client before removing anything and usually disable accounts rather than delete them, so the logs are kept. We then require MFA on the firewall and email, and on desktops where the risk calls for it, and we hold every vendor to the same security standard as the client or higher.
List every outside company that can log in to your network. Confirm each one uses its own account with MFA, that its access is logged, and that it expires when the work ends. Then make sure someone is watching the alerts, and knows what to do when one fires.
Sources
To see where your organization stands on these controls, take the Check Your Security Readiness assessment.
- CrowdStrike, RIBridges Investigation Summary, released by the State of Rhode Island, May 2025
- Governor McKee, Third-party findings on RIBridges data breach released, May 15, 2025
- Governor McKee, Official letters to individuals impacted, January 10, 2025
- Governor McKee, Settlement with Deloitte finalized, April 24, 2026
- State of Rhode Island, RIBridges alert page
- Rhode Island Current, Firewall worked but hundreds of alarms went unnoticed, May 15, 2025
- Rhode Island Current, Data stolen from RIBridges shows up on dark web, December 30, 2024
- Rhode Island Current, Deloitte reaches $6.3M deal to settle class action, October 17, 2025
- U.S. Senate Commerce Committee, A Kill Chain Analysis of the 2013 Target Data Breach, March 26, 2014
- Massachusetts 201 CMR 17.03
- FTC Safeguards Rule, 16 CFR 314.4
- Microsoft Research, How effective is multifactor authentication at deterring cyberattacks?, 2023
Let's Discuss Your IT Needs
Triton Technologies delivers managed IT services, cybersecurity, and IT support for businesses across New England. Contact our team today to start a conversation about your technology environment.
Related articles
- What Do the New Britain and Meriden Ransomware Attacks Mean for Connecticut Businesses? · Sep 29, 2026
- What Happened in the MetroWest Community Federal Credit Union Ransomware Breach in Framingham? · Sep 29, 2026
- What Happened in the Form Energy Ransomware Attack in Somerville, and What Should Employers Learn? · Sep 29, 2026


