RansomHub Strikes Again
Download my Ultimate Guide to Ransomware NOW!
๐ฅ๐ฎ๐ป๐๐ผ๐บ๐๐๐ฏ ๐ฆ๐๐ฟ๐ถ๐ธ๐ฒ๐ ๐๐ด๐ฎ๐ถ๐ป: ๐ง๐๐ผ ๐๐ถ๐ด๐ต-๐ฃ๐ฟ๐ผ๐ณ๐ถ๐น๐ฒ ๐ง๐ฎ๐ฟ๐ด๐ฒ๐๐ ๐๐ฎ๐น๐น ๐ฉ๐ถ๐ฐ๐๐ถ๐บ ๐๐ผ ๐ฆ๐ผ๐ฝ๐ต๐ถ๐๐๐ถ๐ฐ๐ฎ๐๐ฒ๐ฑ ๐ฅ๐ฎ๐ป๐๐ผ๐บ๐๐ฎ๐ฟ๐ฒ ๐๐๐๐ฎ๐ฐ๐ธ
From the Desk of Black Bear MSSP
In recent weeks, two prominent institutions have fallen prey to a devastating ransomware attack carried out by the notorious group, RansomHub. Millinocket Regional Hospital in Maine and Cardiology of Virginia are the latest casualties in a growing list of high-profile targets that have been exploited by this sophisticated threat actor.
๐ ๐ถ๐น๐น๐ถ๐ป๐ผ๐ฐ๐ธ๐ฒ๐ ๐ฅ๐ฒ๐ด๐ถ๐ผ๐ป๐ฎ๐น ๐๐ผ๐๐ฝ๐ถ๐๐ฎ๐น: ๐ ๐๐ฟ๐ถ๐๐ถ๐ฐ๐ฎ๐น ๐๐ฐ๐ฐ๐ฒ๐๐ ๐๐ผ๐๐ฝ๐ถ๐๐ฎ๐น ๐๐ถ๐๐ต ๐ฆ๐ฒ๐ป๐๐ถ๐๐ถ๐๐ฒ ๐๐ฎ๐๐ฎ ๐ฎ๐ ๐ฅ๐ถ๐๐ธ
On July 26, 2024, Millinocket Regional Hospital was targeted by RansomHub, who claimed to have exfiltrated 10 GB of sensitive data from the hospital's systems. The attackers' primary vector is believed to be phishing emails or exploiting unpatched software vulnerabilities.
๐ง๐ต๐ฒ ๐ฐ๐ผ๐บ๐ฝ๐ฟ๐ผ๐บ๐ถ๐๐ฒ๐ฑ ๐ฑ๐ฎ๐๐ฎ ๐ถ๐ป๐ฐ๐น๐๐ฑ๐ฒ๐:
Names
Addresses
Social Security numbers
Medical treatments
Health insurance information
๐๐ฎ๐ฟ๐ฑ๐ถ๐ผ๐น๐ผ๐ด๐ ๐ผ๐ณ ๐ฉ๐ถ๐ฟ๐ด๐ถ๐ป๐ถ๐ฎ: ๐ ๐ง๐ฎ๐ฟ๐ด๐ฒ๐ ๐ณ๐ผ๐ฟ ๐ฅ๐ฎ๐ป๐๐ผ๐บ๐๐๐ฏ'๐ ๐ฆ๐ผ๐ฝ๐ต๐ถ๐๐๐ถ๐ฐ๐ฎ๐๐ฒ๐ฑ ๐๐ฝ๐ฝ๐ฟ๐ผ๐ฎ๐ฐ๐ต
In a separate incident, Cardiology of Virginia was hit by RansomHub in September 2024. The exact threat vector used is still unknown, but the attack suggests that the group has refined its tactics to bypass traditional security measures.
๐ง๐ต๐ฒ ๐ฐ๐ผ๐บ๐ฝ๐ฟ๐ผ๐บ๐ถ๐๐ฒ๐ฑ ๐ฑ๐ฎ๐๐ฎ ๐ถ๐ป๐ฐ๐น๐๐ฑ๐ฒ๐:
Client information (no further details available)
๐ช๐ต๐ฎ๐ ๐๐ฎ๐ป ๐ฃ๐ฎ๐๐ถ๐ฒ๐ป๐๐ ๐๐ผ ๐๐ณ ๐ง๐ต๐ฒ๐ ๐ฆ๐๐๐ฝ๐ฒ๐ฐ๐ ๐ง๐ต๐ฒ๐ถ๐ฟ ๐ฃ๐ฒ๐ฟ๐๐ผ๐ป๐ฎ๐น ๐๐ป๐ณ๐ผ๐ฟ๐บ๐ฎ๐๐ถ๐ผ๐ป ๐ช๐ฎ๐ ๐๐ผ๐บ๐ฝ๐ฟ๐ผ๐บ๐ถ๐๐ฒ๐ฑ?
If you suspect your personal information was compromised in either of these incidents, it's essential to take immediate action. Here are some steps you can follow:
Monitor Your Credit Reports : Keep a close eye on your credit reports and statements for any suspicious activity.
Contact the Hospital or Cardiology Clinic : Reach out to Millinocket Regional Hospital or Cardiology of Virginia directly to inquire about the status of their investigation and what steps they are taking to protect patient data.
Report Any Incidents : If you notice any unusual transactions or discrepancies on your accounts, report them to the relevant authorities immediately.
๐ง๐ต๐ฒ ๐๐ฟ๐ผ๐๐ถ๐ป๐ด ๐ง๐ต๐ฟ๐ฒ๐ฎ๐ ๐ผ๐ณ ๐ฅ๐ฎ๐ป๐๐ผ๐บ๐๐๐ฏ: ๐ช๐ต๐ฎ๐ ๐ช๐ฒ ๐๐ป๐ผ๐ ๐ฆ๐ผ ๐๐ฎ๐ฟ
RansomHub is a relatively new ransomware group believed to have roots in Russia. They operate as a Ransomware-as-a-Service (RaaS) group, where affiliates receive 80% of the ransom paid by victims, while the group takes 20%. This business model makes it more challenging for law enforcement and cybersecurity experts to track down the perpetrators.
Download my guide on ransomware protection:
Stay informed, stay safe!