Healthcare giant UHS hit by ransomware attack, sources say

The attack hit UHS systems early on Sunday morning, according to two people with direct knowledge of the incident, locking computers and phone systems at several UHS facilities across the country, including in California and Florida.

One of the people said the computer screens changed with text that referenced the shadow universe, consistent with the Ryuk ransomware.

The Ryuk ransomware is linked to a Russian cybercrime group, known as Wizard Spider, according to security firm Crowdstrike.

Ryuks operators are known to go big game hunting and have previously targeted large organizations, including shipping giant Pitney Bowes and the U.S.

Some ransomware operators said earlier this year that they would not attack health organizations and hospitals during the COVID-19 pandemic, but Ryuks operators did not.

Last week, police in Germany launched a homicide investigation after the death of a woman, who was diverted to another hospital following a ransomware attack.

Original article
Author: Zack Whittaker

Zack Whittaker writes about cybersecurity for TechCrunch. You can send tips securely via Signal and WhatsApp to +1 646-755-8849, and his PGP fingerprint for email is: 4D0E 92F2 E36A EC51 DAAE 5D97 CB8C 15FA EB6C EEA5. He can also be reached by email: zack.whittaker@techcrunch.com.

Zack Whittaker has recently written 6 articles on similar topics including :
  1. "How did a 17-year-old become the most powerful person on Twitter? Plus, more on the Garmin ransomware attack". (August 4, 2020)
  2. "Maze, a data-stealing ransomware, typically publishes the data if a ransom is not paid". (April 18, 2020)
  3. "A ransomware group known as CLOP was behind the March attack". (April 27, 2020)
  4. "Exclusive: The electronics maker, which builds nuclear electronics modules for the Navy, was infected with a data-stealing strain of ransomware". (March 26, 2020)
  5. "Exclusive: The radar and electronic warfare technology maker was knocked offline in January and recovery is still under way". (March 5, 2020)
  6. "The WastedLocker ransomware, used by a notorious Russian hacking group, is said to be to blame". (July 25, 2020)
Posted on  , , ,