Group Health Cooperative of South Central Wisconsin (GHC-SCW) has disclosed a ransomware attack that took place in January and resulted in a breach affecting more than 500,000 people. Hackers were able to steal documents containing personal and medical information.

However, the compromised devices were not encrypted , so GHC-SCW was able to secure its systems with the help of external cybersecurity experts. Additionally, the systems were brought back online aftera brief outage to contain the breach.
“ In the early morning hours of January 25, 2024, GHC-SCW detected unauthorized access to its network. Its IT Department intentionally isolated and secured the network, resulting in many of its systems being temporarily unavailable ,” the nonprofit healthcare provider said
See also: Change Healthcare faces second ransomware attack
A few days later (February 9) and after an investigation had been initiated, it was discovered that the ransomware gang had copied some of data , which included protected health information (PHI). In addition, the ransomware gang contacted GHC-SCW and claimed responsibility for the attack and data breach.
The health data stolen in the January attack includes names, addresses, phone numbers, email addresses, dates of birth and/or death, Social Security numbers, membership numbers, and Medicare and/or Medicaid numbers.

According to information shared with the U.S. Department of Health and Human Services, the GHC-SCW data breach affected 533,809 people.
In response to the incident, GHC-SCW says it has taken security measures to prevent future attacks, including strengthening existing controls, backing up data, and educating users.
Users are urged to monitor all communications from healthcare providers, including emails, messages, billing statements, and other communications, and to immediately report any suspicious activity to GHC-SCW.
See also: Ransomware attacks to decrease in 2024
Impact on patients
The ransomware attack at GHC-SCW has significant implications for patients . First, the personal and medical information of more than 500,000 individuals has been compromised, increasing the risk to patient privacy and security.
Second, it caused a temporary disruption to the delivery of healthcare services. Ransomware attacks often paralyze IT systems, which can result in the delay or suspension of medical services.
Third, patient trust in GHC-SCW may have been undermined . Patients expect healthcare providers to protect their sensitive information, and this breach may result in a loss of their trust.
Finally, patients may experience additional anxiety and worry due to the attack. The threat of identity theft or other forms of fraud can cause significant stress.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Ransomware gang uses new trick to collect ransom

BlackSuit ransomware
GHC-SCW did not reveal the name of the group behind the January breach, but the BlackSuit claimed responsibility in March.
According to the perpetrators' claims, the stolen files also contain patient financial information, employee data, business contracts, and email correspondence.
At the moment, not much is known about the group, but last June, the Royal ransomware – believed to be the direct successor to Conti – began testing a new encryptor called BlackSuit. Royal has since been renamed BlackSuit.
The FBI and CISA revealed in November that the Royal ransomware gang had breached the networks of at least 350 organizations worldwide since September 2022.
Source: www.bleepingcomputer.com
