
Lorien Health Services in Maryland announced that it was the victim a ransomware attack Data of was stolen and then encrypted in early June. .
The attack is attributed to the operators of the Netwalker ransomware, who leaked the informationwhen the service refused to pay the ransom demanded.
Access to personal information
The health and elderly care service has 9 facilities in four counties (Baltimore, Carroll, Harford and Howard) as well as a rehabilitation center.
Lorien Health Services said the incident was discovered on June 6.The service immediately hired cybersecurity experts to conduct an investigation.
After four days, it was revealed that the ransomware gang had gained access to the personal information of seniors. The data exposed includes: names, social security numbers, dates of birth, addresses, and information . The hackers also gained access to personnel data.
According to the breach notification, sent to the Secretary of Health and Human Services, the number of people affected is 47.754.
Lorien Health Services announced the breach now, but the operators of the Netwalker ransomware had disclosed the incident as early as mid-June, publishing screenshots of files and directories to prove the breach.

Netwalker ransomware gang leaks Lorien Health Services data
As we mentioned above, hackers have already leaked some of data online. A 147MB password-protected file is currently available via a file-.
The hackers also published the key to unlock the file and named the file “Part 1”, indicating that more data may be leaked in the future.
Netwalker ransomware launched under the name Mailto in October 2019 and was renamed to Netwalker in February of this year.
Its targets include corporate networks vulnerable to remote attacks. But as the attack on Lorien Health Services shows, hackers are not picky with their targets.
As is usually the case with these attacks, the agency notified the FBI and provided details that may help in apprehending the perpetrators.
Lorien Health Services sent letters to “all people who may have been affected” on June 16, two days after the hackers announced their successful attack. The letters included details about the ransomware attack and options to protect personal information. The service also offers free credit monitoring and identity protection services.
