Healthcare

Industry

French Oncology Hospital Suspends Treatments for 4 Days after Ransomware Attack

November 15, 2022

Saint-Jean Oncology and Radiotherapy Center was the victim of a ransomware-type cyberattack affecting its Saint-Doulchard and Moulins sites. This paralyzed its information system. It affected all data, in particular patient files (administrative data, medical and technical data).

The Center was forced to suspend its chemotherapy and radiotherapy activities from November 15 to 18, 202 . For these services access to the computerized patient file is essential (ballistics, assays, reports, etc.).

read more

Outage at Leading Public Medical Institute in India affects Hundreds of Patients and Doctors

November 23, 2022

India’s leading public medical institute, All India Institute of Medical Services, or AIIMS, is experiencing outages following a cyberattack.

AIIMS officials told TechCrunch that patient care services have been badly impacted since early Wednesday. The medical institute moved to manual operations, including writing patient notes by hand, as the server recording patient data stopped working. The outages have resulted in long queues and errors in handling emergency cases and continued till Thursday.
Details of whether the attackers could access any patient data have yet to be publicly announced.

UPDATE [03Jul23]: Former cybersecurity chief says the ransomware attack on AIIMS prompted government to make cyber response framework. “A lot of lessons have come out from the incident from a government point of view, and these will, hopefully be implemented.” As reported by Hindustan Times.

read more

Ransomware Attack at Columbian Multinational Healthcare Provider Disrupts Operations

November 27, 2022

The Keralty healthcare organization had its company and subsidiary websites and operations disrupted by a RansomHouse ransomware attack. The Columbian healthcare provider Keralty and its subsidiaries, EPS Sanitas and Colsanitas, suffered disruption to their IT operations, the scheduling of medical appointments and its websites.IT outages have impacted Columbia’s healthcare system, where patients had to wait for over twelve hours to receive care and some fainted due to lack of medical attention.

Keralty is a Colombian healthcare provider and operates in Latin America, Spain, the US, and Asia.

read more

Cyberattack at Osaka Hospital Halted Non-Emergency Services

October 31, 2022

Osaka General Medical Centre issued a statement that the ransomware attack temporarily disrupted the facility’s electronic medical record system. It has stopped providing outpatient care and postponed non-emergency surgeries. The medical centre’s Sumiyoshi Ward is still performing emergency operations.

Hospital staff noticed unusual activity in the hospital’s network in the early hours of October 31. Soon after, they received a message from the threat actors saying: “All files have been encrypted. Please pay in bitcoin for recovery. The amount depends on how quickly you email us.” Staff are working to restore the system and using paper medical records until the incident is resolved.

read more

Louisiana Hospital Disclosed Hackers Accessed Systems

October 1, 2022

Hackers accessed the personal data of nearly 270,000 patients in an attempted ransomware attack on Lake Charles Memorial Health System. LCMH thwarted the hackers’ attempt to encrypt its computers and prevented any disruption to patient care, according to spokesperson Allison Livingston. The health care provider’s own security team detected the hack.

read more

Overly Delayed Disclosure of Ransomware Attack at Australian Clinical Labs

February 12, 2022

On October 31, Australian Clinical Labs (ACL) disclosed a February 2022 data breach that impacted its Medlab Pathology business. The breach exposed the medical records and other sensitive information of 223,000 people.

Quantum ransomware gang took responsibility for the attack. 86GB stolen files were uploaded on its Tor site on June 14, 2022. Leaked data included patient and employee details, financial reports, invoices, contracts, forms, subpoenas, and other private documents. According to Quantum ransomware’s website, the data leak page for MedLab has been accessed 130,000 times.

read more

Lockbit Ransomware Gang Say Japan Hospital Paid $30K Ransom

October 31, 2021

Russian hackers claim a Japanese hospital paid $30,000 to regain access to electronic medical records. The records were encrypted in a ransomware attack last October, causing major disruption to the medical institution’s operations.

At the time of the Oct. 31 attack, Handa Hospital refused to pay the ransom. The hospital said it will build a new electronic medical record system at a cost of 200 million yen.

The town of Tsurugi, which runs the targeted Hospital, has denied paying ransom money. Experts suspect that an IT firm involved in attempts to restore access to the records secretly reached a deal with the hackers.

Japanese police have been urging those targeted in ransomware attacks to not pay money demanded of them.

read more

Australian Health Insurance Firm Medibank Hit by Ransomware Attack

October 12, 2022

Major Australian health insurance provider Medibank Private Limited disclosed being hit by a ransomware attack on October 12. The attack resulted in a temporary service outage, which has since been resolved. The company claim that no systems were encrypted during the attack.

UPDATE 07Nov22: Medibank Says Hacker Accessed Data Of 9.7 Million Customers, Refuses To Pay Ransom

read more

CommonSpirit, a Large US Hospital Chain, Patient Care Impacted by Ransomware Attack.

October 3, 2022

One of the largest hospital chains in the U.S. was hit with a suspected ransomware attack this week. The attack lead to delayed surgeries, hold ups in patient care and rescheduled doctor appointments across the country. Multiple hospitals were affected, including CHI Memorial Hospital in Tennessee, some St. Luke’s hospitals in Texas, and Virginia Mason Franciscan Health in Seattle.

read more

Patient Dies After Hackers Hit ‘Wrong’ Hospital in Germany

September 10, 2020

University Hospital Düsseldorf (UKD) in Germany suffered a cyberattack. Through an unpatched vulnerability, hackers penetrated the hospital’s network with ransomware, forcing planned and outpatient treatments and emergency care to have to occur elsewhere. A patient died after being forced to go to another hospital.

The ransom notes left on the hospital’s encrypted servers were incorrectly addressed to Heinrich Heine University, rather than the hospital itself. After the police contacted the threat actors and explained that they encrypted a hospital, the ransomware operators withdrew the ransom demand and provided a decryption key.

read more