Healthcare

Industry

2020 Phishing Email Cost UK Interserve more than £11M

May 8, 2020

Hackers stole sensitive details on 100,000 people from an outsourcing company named Interserve. The Phishing campaign attackers are unknown and the company offered no additional information. The data stolen is sensitive, including employee names and their addresses, bank details, payroll information, HR records, pension information and much more.

Update August 2023: The Information Commissioner fined Interserve £4.4m in autumn 2022. Interserve was once a FTSE 250 firm but has largely been broken up after collapsing into administration four years ago. Its latest accounts reveal that it spent £7m on ‘professional adviser fees’ following the attack.

read more

Cyberattack Suspends Clinical Activity in Madeira Health Service

August 6, 2023

Cyberattack forces suspension of clinical activity in the Madeira Health Service. Non-urgent clinical activity will be suspended on Monday.
The Madeira Health Service (SESARAM) was the target of a cyber attack that caused a “dysfunction in its computer network”, said the institution, informing that non-urgent clinical activity will be suspended on Monday 7 August. The institution stated: “All non-urgent clinical activity will be suspended for the day tomorrow [Monday, August 7].” This includes consultations, scheduled surgeries and clinical analyzes and complementary means of diagnosis.

The attack compromised compromised the personal data of more than 250,000 Madeirans and 10,000 foreigners. Although there is no ransom demand for the information, the attack has already been claimed by the Rhysida group.

read more

16 Hospitals of Prospect Medical Holdings Impacted by Ransomware Attack

August 3, 2023

The 16 hospitals run by Prospect Medical Holdings are still recovering from a ransomware attack announced last Thursday that caused severe outages at facilities in four states. Several of the hospitals were forced to divert ambulances to other healthcare facilities, cancel appointments and close smaller clinics while the parent company dealt with the attack. The incident has drawn national headlines due to how widespread it is, covering healthcare facilities in multiple states.

While the FBI and the U.S. Department of Health and Human Services (HHS) declined to comment on the perpetrators, HHS published a warning to all hospitals on Friday about Rhysida, noting that it was a relatively new ransomware-as-a-service (RaaS) group that emerged in May.

read more

BlackCat Ransomware Attack at Lehigh Valley Health Network

January 8, 2023

Lehigh Valley Health Network has confirmed that its Jan. 8 cyberattack was conducted by Russian ransomware gang BlackCat. On June 29, 2023 the health system notified patients that the breach from BlackCat occurred on Jan. 8, with the health system detecting the ransomware on its IT system on Feb. 6.

BlackCat was able to obtain some patients’ protected health information including email addresses, banking information, medical information, Social Security numbers and more.

In addition the cybercriminals may have stolen the sensitive photographs of as many as 2,760 patients, officials said Thursday. Some of those images were posted on the dark web. According to the court filing the health care provider suggested a class-action lawsuit over the data breach. That would likely involve more than 100 people and could cost about $55 million.

LVHN also revealed that the hackers responsible for the breach demanded a ransom of over $5 million in February, which officials refused to pay.

read more

Emergency Shut Down at Medical Clinic in TN after Cyberattack

April 22, 2023

A cyberattack on Murfreesboro Medical Clinic & SurgiCenter (MMC) in Tennessee shut down operations for around two weeks.

On April 22, 2023 the network was rapidly shut down to contain the attack. MMC said the action taken limited the damage caused. MMC has been working with cybersecurity experts and law enforcement to investigate the incident and determine the extent of the attack. While those processes were completed, the decision was taken to close all operations.

MMC planned to reopen on a limited basis on May 3, 2023, then restore full operations shortly thereafter. However, the recovery process took longer than planned.

read more

US Hospital Closes 2 Years after Cyberattack: Unprecedented Case

February 20, 2021

St. Margaret’s Health, a hospital in Spring Valley, Ill., announced in May 2023 that it will have to close its doors due to the financial impact of a ransomware attack. That attack, which occurred in 2021, crippled the hospital’s computer systems and prevented financial claims from being submitted to insurance companies and government agencies for several months. This resulted in significant financial difficulties for the facility.

Experts believe this is the first time a hospital has had to close due to a cyberattack.

Hospital management said a combination of factors, including the Covid 19 pandemic, the cyberattack and a shortage of staff, had made it impossible to keep operations going.

read more

Widespread Disruption at Norton Healthcare Operations after Ransomware Attack

May 9, 2023

Norton Healthcare says it has been victimized by a “cyber-event,” and some of its computer network systems have been offline. Patient appointments, surgeries, emergency care and online services were all affected.

The BlackCat ransomware group claims responsibility for the attack and says to have exfiltrated 4.7 TB of data.

The effects of the attack are still impacting the health system’s network and services over a month later. With some communication platforms back in full operation, problems with the distribution of testing and imaging results, and [re]scheduling of procedures, exams persisted.

read more

Data Breach at Luxottica’s Eyemed Vision Affects 820K Patients.

August 5, 2020

Luxottica disclosed that their appointment scheduling application suffered a data breach after being hacked on August 5th, 2020. The breach has exposed the personal and protected health information of 829,454 patients at partner eye care practices. Luxottica’s Eyemed division partners get access to a web-based appointment scheduling application.

This data breach announcement comes on the heels of a Nefilim ransomware attack on Luxottica. This September 2020 attack caused significant outages, interruptions, and theft of unencrypted files.

read more

Ransomware Attack Erases Ambulance Appointments for Next Few Weeks

December 6, 2022

The Trois Cantons ambulances in Peyrehorade were the victims of a ransomware attack. They have lost all their files and appointments for the next few weeks. It is not known which patients were scheduled, or at what times. Telephone numbers are also lost. Patients are invited to call the Three Cantons ambulances as soon as possible on 05 58 73 00 63. The ambulances operated on Wednesday, December 7 “pencil and paper”.

read more

Cyberattack Forces French Hospital to Cancel Operations

December 5, 2022

Hospital Centre of Versailles, near Paris, canceled operations and transfer some patients due to a cyber attack suffered over the weekend.

The computers at the hospital were infected with ransomware, threat actors demanded a ransom.
“A ransom, the amount of which I do not know, has been requested but we do not intend to pay it,” assured Delepierre, who is also mayor of Chesnay-Rocquencourt. Health Minister Francois Braun told AFP that six patients had been transferred from the beginning of the attack evening, three in intensive care and three from the neonatal unit.

The hospital is still facing problems and we cannot exclude that other patients will be transferred in other structures. “While the machines were still functioning in the intensive care unit, more people were needed to watch the screens as they were no longer working as part of a network, Braun said.” reported AFP.

In France, the law prohibits public establishments to pay ransoms.

read more