HHS alerts health care sector to ransomware, data extortion gang

The Department of Health and Human Services recently released an advisory to help health care organizations protect their systems and networks from 8Base, a ransomware and data extortion gang targeting small- and medium-sized organizations in health care and other sectors. Recommendations include prioritizing cybersecurity best practices, from regularly updating and patching systems to educating employees to avoid and report phishing emails and malicious attachments.
鈥淭his emerging ransomware group appears primarily focused on data extortion rather than data encryption at this point,鈥 said John Riggi, AHA鈥檚 national advisor for cybersecurity and risk. 鈥淭heir rapid rise and large number of attacks indicates this group may be a rebranding of a former group or contain elements of a former ransomware group. I have observed a general trend in which ransomware attackers claim to be 鈥榩enetration testers鈥 performing a 鈥榮ervice鈥 and discussion of 鈥榲ulnerability reports鈥 for the victim, raising the possibility that these hackers may be affiliated with 鈥榣egitimate鈥 cybersecurity firms in non-cooperative foreign jurisdictions or have formal cybersecurity training. These data extortion attacks highlight the need to ensure that protected health information (PHI) within our networks, especially PHI outside the electronic medical record, is fully mapped and encrypted at rest and in transit.鈥
For more information on this or other cyber and risk issues, contact Riggi at鈥. For the latest cyber and risk resources and threat intelligence, visit鈥.