BlackCat Ransomware Attack at Lehigh Valley Health Network

July 22, 2023


Lehigh Valley Health Network has confirmed that its Jan. 8 cyberattack was conducted by Russian ransomware gang BlackCat. On June 29, 2023 the health system notified patients that the breach from BlackCat occurred on Jan. 8, with the health system detecting the ransomware on its IT system on Feb. 6.

BlackCat was able to obtain some patients' protected health information including email addresses, banking information, medical information, Social Security numbers and more.

In addition the cybercriminals may have stolen the sensitive photographs of as many as 2,760 patients, officials said Thursday. Some of those images were posted on the dark web. According to the court filing the health care provider suggested a class-action lawsuit over the data breach. That would likely involve more than 100 people and could cost about $55 million.

LVHN also revealed that the hackers responsible for the breach demanded a ransom of over $5 million in February, which officials refused to pay.

Incident Date

January 8, 2023

Estimated Cost

unknown, possibly $55M

Type of Malware

No Malware identified

Threat Source