Healthcare giant UHS hit by ransomware attack, sources say

The attack hit UHS systems early on Sunday morning, according to two people with direct knowledge of the incident, locking computers and phone systems at several UHS facilities across the country, including in California and Florida.

One of the people said the computer screens changed with text that referenced the shadow universe, consistent with the Ryuk ransomware.

The Ryuk ransomware is linked to a Russian cybercrime group, known as Wizard Spider, according to security firm Crowdstrike.

Ryuks operators are known to go big game hunting and have previously targeted large organizations, including shipping giant Pitney Bowes and the U.S.

Some ransomware operators said earlier this year that they would not attack health organizations and hospitals during the COVID-19 pandemic, but Ryuks operators did not.

Last week, police in Germany launched a homicide investigation after the death of a woman, who was diverted to another hospital following a ransomware attack.

Original article
Author: Zack Whittaker

Zack Whittaker writes about cybersecurity for TechCrunch. You can send tips securely via Signal and WhatsApp to +1 646-755-8849, and his PGP fingerprint for email is: 4D0E 92F2 E36A EC51 DAAE 5D97 CB8C 15FA EB6C EEA5. He can also be reached by email: zack.whittaker@techcrunch.com.

Zack Whittaker has recently written 6 articles on similar topics including :
  1. "This week's Decrypted looks at Palantir's risk factors ahead of its IPO". (August 31, 2020)
  2. "The Snake ransomware is believed to be the cause". (June 9, 2020)
  3. "The WastedLocker ransomware, used by a notorious Russian hacking group, is said to be to blame". (July 25, 2020)
  4. "The company has 55 fertility clinics across the U.S". (November 26, 2020)
  5. "Exclusive: The electronics maker, which builds nuclear electronics modules for the Navy, was infected with a data-stealing strain of ransomware". (March 26, 2020)
  6. "How did a 17-year-old become the most powerful person on Twitter? Plus, more on the Garmin ransomware attack". (August 4, 2020)
Posted on  , , ,