Australian IVF giant Genea breached by Termite ransomware gang

Like other ransomware gangs, the Termite cybercrime group is involved in data theft, extortion, and encryption attacks. According to cybersecurity firm Trend Micro, they're using a version of the Babuk encryptor leaked in September 2021 and are known to drop a "How To Restore Your Files.txt" ransom note on the victims' encrypted systems. ​The Termite ransomware gang has claimed responsibility for breaching and stealing sensitive healthcare data belonging to Genea patients, one of Australia's largest fertility services providers. The IVF (in vitro fertilization) provider has been operating since 1986 (when it was known as Sydney IVF). It offers a wide range of services, including fertility treatments, tests, genetic services, preservation options, and donor programs, in 22 fertility clinics in New South Wales, South Australia, Western Australia, Melbourne, Canberra, and Queensland. Termite is a ransomware operation that surfaced in mid-October, according to threat intelligence company Cyjax, and has since listed 18 victims on its dark web portal from all over the world and various industry sectors. While Genea didn't attribute the attack to a specific threat group or cybercrime operation, the Termite ransomware gang claimed responsibility on Monday. The company said it obtained a court-ordered injunction to prevent the leaked data from being shared by others, and it's also working with the Office of the Australian Information Commissioner and the Australian Cyber Security Centre to investigate an incident. In a new entry on their dark web leak site, they said they stole roughly 700GB of data and leaked screenshots of identification documents and patients' files allegedly stolen from Genea's network. The redacted court order reveals that the threat actors breached Genea's network on January 31, 2025, through a Citrix server.

This Cyber News was published on www.bleepingcomputer.com. Publication date: Wed, 26 Feb 2025 13:35:17 +0000


Cyber News related to Australian IVF giant Genea breached by Termite ransomware gang

Australian IVF giant Genea breached by Termite ransomware gang - Like other ransomware gangs, the Termite cybercrime group is involved in data theft, extortion, and encryption attacks. According to cybersecurity firm Trend Micro, they're using a version of the Babuk encryptor leaked in ...
10 months ago Bleepingcomputer.com
Australian IVF provider Genea confirms hackers accessed patients' healthcare data | The Record from Recorded Future News - One of Australia's largest fertility services providers, Genea, said on Wednesday that data stolen during a recent cyberattack on its systems had been published online by hackers. According to local media reports, people struggled to reach the ...
10 months ago Therecord.media
Australian fertility services giant Genea hit by security breach - While the company has yet to reveal when the breach was detected or whether patients' personal and health information was exposed, Genea's breach confirmation comes five days after a phone outage impacted the group's fertility clinics. ​Genea, ...
11 months ago Bleepingcomputer.com
10 Best Ransomware Protection Tools - 2025 - It protects devices from ransomware and other cyber threats using advanced threat intelligence, behavioral analysis, and cloud-based technology. It monitors and prevents ransomware assaults on personal files and automatically restores encrypted ...
11 months ago Cybersecuritynews.com
10 Best Ransomware File Decryptor Tools in 2025 - Kaspersky Rakhni Decryptor contains different decryption tools based on various versions of Rakhni ransomware and helps you decrypt encrypted files on your system. PyLocky Ransomware Decryption Tool is a free and open source developed and released by ...
9 months ago Cybersecuritynews.com
Genea IVF Clinic Breached - Thousand of Patient Data at Risk - While the full extent of the breach remains unclear, Genea has confirmed that its patient management systems were accessed, potentially exposing personal information such as names, emails, phone numbers, medical histories, and test results. Genea, ...
10 months ago Cybersecuritynews.com
The Week in Ransomware - Earlier this month, the BlackCat/ALPHV ransomware operation suffered a five-day disruption to their Tor data leak and negotiation sites, rumored to be caused by a law enforcement action. The FBI revealed this week that they hacked the BlackCat/ALPHV ...
2 years ago Bleepingcomputer.com LockBit Akira Noescape
The Week in Ransomware - Governments struck back this week against members of ransomware operations, imposing sanctions on one threat actor and sentencing another to prison. On Tuesday, the Australian, US, and UK governments announced sanctions against Aleksandr Gennadievich ...
1 year ago Bleepingcomputer.com LockBit BianLian Akira Cactus
The Week in Ransomware - This week was pretty quiet on the ransomware front, with most of the attention on the seizure of the BreachForums data theft forum. That does not mean there was nothing of interest released this week about ransomware. A report by CISA said that the ...
1 year ago Bleepingcomputer.com LockBit Inc ransom Black Basta
DP World confirms data stolen in cyberattack, no ransomware used - International logistics giant DP World has confirmed that data was stolen during a cyber attack that disrupted its operations in Australia earlier this month. The company says no ransomware payloads or encryption was used in the attack. On November ...
2 years ago Bleepingcomputer.com
The Top 10 Ransomware Groups of 2023 - This article takes an in-depth look at the rise in ransomware attacks over the past year and the criminal groups driving the surge in cyber extortion. LockBit has established itself as one of the most notorious ransomware operations since emerging on ...
2 years ago Securityboulevard.com TA505 8base LockBit BianLian Medusa Noescape Black Basta
Waiting for the BlackCat rebrand - We saw another ransomware operation shut down this week after first getting breached by law enforcement and then targeting critical infrastructure, putting them further in the spotlight of the US government. While the Tor onion domain seizure was a ...
1 year ago Bleepingcomputer.com Medusa Cuba STORMOUS
Hive Ransomware: A Detailed Analysis - This past week, on January 26th, to be exact, the FBI successfully shut down the Hive ransomware group and saved victims over a hundred million dollars in ransom payments and remediation costs. As ransomware continues to be a national security threat ...
2 years ago Heimdalsecurity.com LockBit
FBI Alarmed as Ransomware Strikes 300 Victims, Critical Sectors Under Siege - There was an advisory published late on Monday about the Play ransomware gang that was put out by the Federal Bureau of Investigation together with the US Cybersecurity and Infrastructure Security Agency and the Australian Cyber Security Centre. The ...
2 years ago Cysecurity.news CVE-2022-41040 CVE-2022-40802
Ransomware Roundup - The Ransomware Roundup report aims to provide readers with brief insights into the evolving ransomware landscape and the Fortinet solutions that protect against those variants. This edition of the Ransomware Roundup covers the 8base ransomware. 8base ...
2 years ago Feeds.fortinet.com 8base
Medusa Ransomware Turning Your Files into Stone - Unit 42 Threat Intelligence analysts have noticed an escalation in Medusa ransomware activities and a shift in tactics toward extortion, characterized by the introduction in early 2023 of their dedicated leak site called the Medusa Blog. The Unit 42 ...
2 years ago Unit42.paloaltonetworks.com Medusa
ALPHV ransomware site outage rumored to be caused by law enforcement - A law enforcement operation is rumored to be behind an outage affecting ALPHV ransomware gang's websites over the last 30 hours. The ALPHV negotiation and data leak sites suddenly became unavailable yesterday and continue to remain down today. ...
2 years ago Bleepingcomputer.com Ragnar Locker
FBI: ALPHV ransomware raked in $300 million from over 1,000 victims - The ALPHV/BlackCat ransomware gang has made over $300 million in ransom payments from more than 1,000 victims worldwide as of September 2023, according to the Federal Bureau of Investigation. In the joint advisory published today in collaboration ...
2 years ago Bleepingcomputer.com LockBit Noescape
FBI: Play ransomware breached 300 victims, including critical orgs - The Federal Bureau of Investigation says the Play ransomware gang has breached roughly 300 organizations worldwide between June 2022 and October 2023, some of them critical infrastructure entities. The warning comes as a joint advisory issued in ...
2 years ago Bleepingcomputer.com Rhysida
Uncertainty Is the Biggest Challenge to Australia's Cyber Security Strategy - Political shifts could lead to changes in Australia's cyber security strategy. Early in 2023, as the Australian government started to craft its cyber security vision, it met with opposition at both ends of the political spectrum. On the right wing, ...
2 years ago Techrepublic.com
How ransomware gangs are engaging - As ransomware gangs continue to market themselves as legitimate businesses complete with customer service representatives, new research from Sophos showed that threat actors are expanding public relations efforts to further pressure victims into ...
2 years ago Techtarget.com LockBit Snatch
The Week in Ransomware - Today's column brings you two weeks of information on the latest ransomware attacks and research after we skipped last week's article. BleepingComputer has learned that some of the BlackCat/ALPHV affiliates are not buying the explanation and have ...
2 years ago Bleepingcomputer.com LockBit Qilin Noescape
Nissan Australia cyberattack claimed by Akira ransomware gang - Today, the Akira ransomware gang claimed that it breached the network of Nissan Australia, the Australian division of Japanese car maker Nissan. In a new entry added to the operation's date leak blog on December 22, Akira says that its operators ...
2 years ago Bleepingcomputer.com Akira Qilin
Researchers link 3AM ransomware to Conti, Royal cybercrime gangs - Security researchers analyzing the activity of the recently emerged 3AM ransomware operation uncovered close connections with infamous groups, such as the Conti syndicate and the Royal ransomware gang. The 3AM ransomware gang's activity was first ...
2 years ago Bleepingcomputer.com Blacksuit LockBit Threeam
The Week in Ransomware - Attacks on hospitals continued this week, with ransomware operations disrupting patient care as they force organization to respond to cyberattacks. While many, like LockBit, claim to have policies in place to avoid encryping hospitals, we continue to ...
1 year ago Bleepingcomputer.com LockBit Cactus