The LockBit ransomware gang over the weekend claimed responsibility for a November 2023 cyberattack on hospital system Capital Health.
In December, Capital Health announced that it fell victim to a cyberattack that resulted in network outages, and that it immediately launched an investigation, informed law enforcement, and started the restoration process.
Capital Health also noted that it was working with a forensics firm to determine impact on patient and employee data.
The healthcare organization did not provide specific details on the type of cyberattack it suffered and it appears that file-encrypting malware was not deployed on its systems.
According to the LockBit ransomware gang, only data exfiltration occurred.
The ransomware group says it stole more than 10 million files from the healthcare organization, which allegedly includes medical confidentiality data.
The cybercriminals also note that they have only compromised the Capital Health Regional Medical Center, a Trenton, New Jersey-based member of the Capital Health system.
The LockBit group added Capital Health to its leak site on January 7, threatening to make the allegedly stolen information public today, unless a ransom is paid.
The gang claims that the stolen data is worth roughly $250,000.
In 2023, tens of millions of individuals in the US were impacted by data breaches at healthcare providers and their business partners.
This Cyber News was published on www.securityweek.com. Publication date: Tue, 09 Jan 2024 14:13:31 +0000