HomeSecurityMcLaren Health Care - Blackcat ransomware: Patient data leak on the dark web?

McLaren Health Care – Blackcat ransomware: Patient data leaked to the dark web?

McLaren Health Care reported that the ransomware (Blackcat) attack that hit 14 of its hospitals in Michigan in August and September may have also led to patient data being breached and leaked onto the dark web.

The well-known ransomware gang Blackcat/AlphV claimed responsibility for the cyberattack last week, posting online that it had stolen 6 terabytes of McLaren data , including the personal information of 2.5 million patients .

McLaren Health Care

It will be one of the biggest leaks of all time,” the BlackCat/AlphV team wrote in the posts. “... Our backdoor is still operating on your network.”

The Free Press first reportedin early September that McLaren Health Care's billing and electronic medical records systems were hit by a cyberattack, forcing employees to use personal cell phones to communicate.

See also: Blackbaud: $49.5 million to settle ransomware lawsuit

McLaren Health Care issued the following update this week regarding the ransomware attack and patient data breach:

Protecting the security and privacy of data on our systems is a top priority, so we immediately launched a comprehensive investigation to understand the source of the outage and determine if there was any data. At the same time, we reached out to leading cybersecurity experts to assist in investigation and were in contact with law enforcement. We have also taken steps to further strengthen our cybersecurity posture, with a focus on further securing our systems, and limiting disruption to our patients and the communities we serve.

Based on our investigation, we have determined that we have been impacted by a ransomware attack. We are investigating reports that some of our data may be available on the dark web and will notify individuals whose information was affected, if any, as soon as possible. We want to assure our patients and the communities we serve that our systems remain operational and we continue to provide the exceptional care we are known for.“.

See also: Number of victims reporting to ransomware gang “leak sites” increases

According to the Free Press, a McLaren Health Care spokesperson said that at least some of the claims made by the BlackCat/AlphV have not been confirmed. For example, the company and experts' analysis found no evidence of a backdoor on the systems.

However, we still do not know exactly when the cyberattack and what information was stolen.

Blackcat ransomware data breach

BlackCat ransomware

BlackCat, a criminal group with ties to Russia, has previously carried out a ransomware attack against a healthcare .

And in that case, hackers had stolen patient data and were threatening to leak it.

See also: Cuba ransomware: Attack on Wisconsin health department

Cybercriminals started targeting patients, saying: “Hey, we have your mammograms. And we’re going to leak them because your clinic doesn’t want to pay the ransom. But if you pay us, your personal files won’t be leaked along with everyone else’s.”

Healthcare providers are required to report any health information breach to the U.S. Department of Health and Human Services, as well as the Federal Trade Commission.

In July, Trustwave, a Chicago-based cybersecurity company, published a report that said 24% of all cyberattacks in the U.S. in 2022 targeted the healthcare.

dark web
McLaren Health Care – Blackcat ransomware: Patient data leaked to the dark web?

Ransomware attacks on healthcare organizations

The rise of ransomware attacks in the healthcare sector is a worrying trend that requires constant attention and defensive strategies. As demonstrated by the recent attack on McLaren, attackers are threatening not only the functionality of medical systems, but also the security of patient data. 

In the McLaren attack, patient data may have been leaked onto the dark web, threatening the personal security and privacy of people who trust these medical institutions for their treatment.

Protecting patient data is more important than ever

Medical facilities need to review and strengthen their cybersecurity strategies, including training staff on ransomware threats. It is also crucial to continuously monitor to detect and stop attacks before they cause serious damage. 

Without these security measures, ransomware attacks will continue to pose a threat to healthcare providers and their patients. Continued vigilance and decisive action are essential to protect our most vulnerable citizens and keep their personal and medical data safe in the digital age.

Source: eu.freep.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS