MIT TRACE

MIT CTL Logo
Back to Main Dashboard

RIBridges breach forces Rhode Island benefits system offline for more than a month

Rhode Island was notified on 05/12/2024 of suspicious activity in the Deloitte-managed RIBridges environment, later confirmed as a breach. Subsequent investigation found unauthorized use of Deloitte credentials, access to multiple systems and exfiltration of files. The State took RIBridges offline on 13/12/2024; customers could not access the portal or mobile app, and only a limited phased relaunch began in late January 2025, materially interrupting digital delivery of health and human-services benefits.

83

Estimated severity

83 / 100

95

Source reliability

95 / 100

Approximate Date

05/12/2024

Targeted Company

STATE OF RHODE ISLAND

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

United States

USA

Other Affected Countries

No other affected countries reported

Target country

United States

Affected countries

United States

Impacted regions

Rhode Island · United States

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Service unavailabilityOperational disruption

Affected sectors

Government & Public Administration

Affected departments

Information Technology

Attack Profile

Attack types

Use of stolen credentialsUnauthorized accessData exfiltrationExtortion

Attributed threat actors

BRAIN CIPHER

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.