Ransomware gangs allegedly hit two major US healthcare firms, 300,000 patients have data stolen

security
(Image credit: Shutterstock / binarydesign)

  • Two US healthcare firms confirmed suffering a cyberattack
  • More than 300,000 victims have had sensitive data stolen
  • Rhysida claimed responsibility for the attack and added the data to its leak site

Ransomware operators Rhysida are claiming responsibility for cyberattacks on two US healthcare organizations.

On its data leak site, they listed Sunflower Medical Group, and Community Care Alliance (CCA). The former is a healthcare provider in the Kansas City metropolitan area offering services such as primary care, urgent care, pediatrics, and more. The latter is a unified human service agency offering more than 50 programs.

Combined, it seems that more than 300,000 people have had their sensitive data compromised as a result of these attacks.

No abuse yet

In a public announcement posted on its website, Sunflower said that the attackers broke into the systems on December 15, but were only spotted and ousted a month later, around January 7.

During that time, they stole people’s names, addresses, dates of birth, Social Security numbers, driver’s license numbers, medical information, and health insurance information. In a filing with the Maine Attorney General’s Office, Sunflower said 220,968 people were affected.

CCA, on the other hand, was struck in July last year, and claims that the miscreants took people’s names, addresses, dates of birth, driver's license numbers, and SSNs, as well as diagnoses and conditions, lab results, medications, patient ID numbers, health insurance information, provider names, and other data. Its filing with the Maine Attorney General’s Office puts the number of affected people at 114,945.

As for Rhysida, the ransomware operators claim to have 7.6 TB worth of Sunflower’s data, including a 3TB SQL database, The Register reports. Since the data is still listed on the site, it means either that the negotiations are ongoing, or that they’ve broken down.

In any case, Rhysida is yet to leak everything on the dark web, and at press time, there was no indication of abuse in the wild. Both organizations said they tightened up on security following the incident.

Via The Register

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
ID theft
Over a million patients potentially hit after another US healthcare provider hit by cyberattack
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
UK private health services firm told to pay up $2m for ransomware hit
ransomware avast
The biggest addiction treatment provider in the US says it was hit by data breach
An abstract image of padlocks overlaying a digital background.
US healthcare giant Ascension says ransomware attack affected nearly six million customers
Doctor working on laptop
Another major US hospital hacked, data on 1.4 million patients leaked
Lock on Laptop Screen
United Healthcare data breach may have affected 190 million Americans
Latest in Security
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
person at a computer
Many workers are overconfident at spotting phishing attacks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Latest in News
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
An image of the Nintendo Switch 2
Nintendo Switch 2 could have AI upscaling similar to PS5 Pro’s PSSR according to patent, and it could be a gamechanger for graphics on the upcoming console
PowerColor Red Devil AMD RX 9070 XT graphics card shown side-on
Your next GPU could be from AMD, not Nvidia, if Team Red’s success with PC gamers continues
Quordle on a smartphone held in a hand
Quordle hints and answers for Tuesday, March 18 (game #1149)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Tuesday, March 18 (game #380)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Tuesday, March 18 (game #646)