Personal data on over 700,000 exposed by Illinois government agency

  • IDHS accidentally exposed sensitive data of 700,000 people via publicly accessible maps
  • Data included addresses, case details, & medical assistance plan information
  • Access restricted in September 2025; affected individuals notified, but no credit monitoring offered

The Illinois Department of Human Services (IDHS) kept a database on the open internet, exposing sensitive data of 700,000 people to anyone who found it.

In a press release published on the agency’s website in early January, it was said that the IDHS Division of Family and Community Services’ Bureau of Planning and Evaluation, a division that helps plan programs for low-income and vulnerable families, created maps that were supposed to help with resource allocation decisions.

The maps were created to help IDHS “determine where to open new local offices and were intended for internal IDHS use only”. But, these maps were posted on the clearweb, and were thus accessible to all visitors.

Not exploited (yet)

The individuals affected by this incident can be split into two categories, IDHS explained: around 32,000 customers of the Division of Rehabilitation Services, and more than 670,000 Medicaid and Medicare Savings Program recipients.

For the first group, IDHS exposed names, addresses, case numbers, case status, referral source information, region and office information, and status as DRS recipients.

For the second one, exposed information includes addresses, case numbers, demographic information, and the name of medical assistance plans (such as Medicaid, Medicare, etc.). Anyone who believes they might be affected should be wary of identity theft and fraud.

Because of the way these maps were set up, and the data exposed, it is impossible to determine who viewed them and if any malicious actors exfiltrated the information found inside. However, IDHS claims it has seen no evidence of attempted misuse.

The mistake was spotted in late September 2025, and the agency responded by restricting access to authorized employees only. It is now notifying affected individuals and has set up a free number where customers can call for additional inquiries.

There was no word on any identity theft or credit monitoring services as of yet, although these are standard practice in these kinds of situations.

Via The Record

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Truly phoneless AI glasses to the first specs with HDR10 — here are the best smart glasses from CES 2026

Every year CES 2026 is brimming with technological marvels highlighting the gadgets of tomorrow, and in no other category does that feel more true...

2026 could well be the year of the $500 32GB DDR5 memory module — experts predict DDR will go up by 60% in Q1...

DDR5 pricing is already sky high and further increases look likely this yearA 60% DRAM rise could push 32GB DDR5 modules beyond $500Server and...

Dell unveils 52-inch pseudo-6K monitor that’s bound to give you a neck torticollis — but if you want a true 6K experience, don’t buy...

Dell UltraSharp 52 supports dividing the screen into up to four desktopsEach virtual desktop measures 1536 x 2560 when split into four sectionsThe panel...

How to watch A Thousand Blows — stream Stephen Graham boxing drama online from anywhere

The underworld bare-knuckle boxing drama, A Thousand Blows, returns for a second season on January 9, 2026. Created by Steven Knight (the mind behind...

Nvidia partner wants to ‘beautify’ data centers with the Infinity Cube concept — plans to cram 86TB DDR5 and 224 B200 GPU in a...

Odinn Infinity Cube combines multiple Omnia supercomputers into a single glass enclosureMemory capacity reaches 86TB of DDR5 ECC registered RAMNVMe storage in the cube...

I flew the Star Wars Death Star trench run on the Sphere in a Lego X-Wing — and nothing else comes close

The Sphere in Las Vegas has already hosted a run of immersive concerts, films, and experiences inside its walls. But on the outside, its...

Satechi unveils Thunderbolt 5 docking station that doubles as external SSD — shame it doesn’t take HDDs, and why doesn’t it have video outputs...

Satechi CubeDock integrates an NVMe SSD enclosure supporting up to 8TB of storageThe dock includes three Thunderbolt 5, USB-C, and USB-A portsDual 6K displays...

TV makers are taking AI too far

This is Lowpass by Janko Roettgers, a newsletter on the ever-evolving intersection of tech and entertainment, syndicated just for The Verge subscribers once a...

Satechi’s new Slim EX keyboards have a replaceable battery

The Satechi EX3 Wireless Keyboard comes with a number pad and navigation keys. Satechi is launching a new pair of wireless keyboards with a rechargeable...

Microsoft will put buy buttons directly in Copilot

Microsoft is launching a new feature in Copilot that will allow you to make purchases during conversations with the AI chatbot. Now, when you're...