Healthcare ransomware attacks are one example of cyberattacks for the healthcare sector due to the sensitivity of its data. In recent weeks, several attacks and data breaches have been identified, highlighting the sector’s target for ransomware groups and unwanted data exfiltration. The following cases highlight the severity and scope of these attacks.
New Boston Dental Care fell victim to a ransomware attack by the 8BASE group that was disclosed on May 13, 2024. Unlike the NHS Scotland incident, the attackers have provided a download link for the stolen data, and the period for the company to pay the ransom has expired. The compromised files include:
The publication of these files indicates that the negotiation period has ended without a resolution, leading to the public release of sensitive information.
NHS Scotland, the publicly funded healthcare system in Scotland and part of the UK’s National Health Service, was attacked by the INC Ransom group. The attack was publicized on May 11, 2024. The threat actor behind this attack appears to have attempted negotiations with NHS Scotland, but as of now, they have not received a response. Consequently, the data has not yet been leaked.
The compromised data includes:
Currently, no full data has been published as the ransom group seems to be in ongoing contact with NHS Scotland.
At Constella, we have identified several breaches in the healthcare sector over recent weeks, one of the most significant being the Covid19MOVE breach. Detected on April 29, 2024, this breach exposed approximately 12 million records related to Covid-19 patients in Russia. The types of exposed data include:
The data from this breach has not been attributed to a specific company, suggesting it could be a compilation of Covid-19 related data from various sources.
Additionally, at Constella, we have analyzed various sources from the Dark Web and detected that a database containing information from the Saudi Ministry of Health (500 GB), according to the threat actor, this information has recently been put up for sale by a user known as verifiedBpp. The data spans from 2020 to 2024 and includes:
The post’s owner claims that the Ministry of Health’s servers were hacked, with access gained on January 3, 2021, and maintained through March 21, 2024. The total amount of data stolen is estimated to be 500 GB. The owner also mentioned that he could leak 100 GB of this sensitive data if he wants.
Given the recent surge in healthcare ransomware attacks, it’s crucial to take proactive steps to protect our health information. Here are some tips to help safeguard your personal health data against such cyber threats:
By taking these steps, you can help protect your sensitive health information from cyber threats and mitigate the impact of any potential data breaches in the healthcare sector. For more information about how to protect your organization and your patients, contact Constella.
*** This is a Security Bloggers Network syndicated blog from Constella Intelligence authored by Alberto Casares. Read the original post at: https://constella.ai/recent-healthcare-ransomware-attacks/