After the Medusa ransomware infected the systems of state-owned health insurer Philippine Health Insurance Corp. (PhilHealth) on September 22, cybercriminals demanded a ransom of $300,000, or about 16 million Philippine pesos, according to the Department of Information and Communications Technology (DICT) .
See also: Medusa ransomware: PhilHealth paralyzed by attack

"They have already asked for $300,000 to do two things: One is to delete the data they captured and the second is to give us the key so we can decrypt the data they encrypted," DICT Deputy Secretary Jeffrey Ian Dy told The STAR yesterday.
The data stolen from PhilHealth has been published on the Dark Web, he added.
The National Computer Emergency Response Team of the Cybersecurity Office DICT has been activated to investigate the cybercriminals, according to Mr. Dy.
See also: Stealth Falcon hackers use new Deadglyph malware

"The Medusa ransomware, recently observed since June 2021, is distributed by leveraging publicly exposed servers Remote Desktop Protocol brute force, phishing campaigns, or by exploiting existing vulnerabilities," Dy said in an advisory.
"When executed, the Medusa ransomware terminates more than 280 Windows for programs that could prevent file encryption," he added.
Dy said containment measures have been taken and that the system should be back up and running today. PhilHealth chairman Emmanuel Ledesma Jr.said no personal or medical information has been compromised or leaked.
See also: Ransomware: White House urges dozens of countries to pledge not to pay ransoms
Philippine Health Insurance Corp. (PhilHealth) is the main government-owned health insurance company in the Philippines. It offers comprehensive insurance services, protecting citizens from high medical costs and providing insurance coverage for a wide range of medical events and conditions.
