Fred Hutch failed to reveal threats of potential swatting attacks until this site revealed the threat. Should they have disclosed it themselves?

On December 28, DataBreaches published snippets from a chat with a threat actor (TA) who claimed to have involvement with both the Fred Hutch cyberattack and the Integris cyberattack. In the course of that exchange, the TA surprised DataBreaches by cla… Continue reading Fred Hutch failed to reveal threats of potential swatting attacks until this site revealed the threat. Should they have disclosed it themselves?

Family Healthcare notifying patients of November 2022 breach at Brady Martz & Associates

On September 8, Brady Martz & Associates in North Dakota disclosed a data breach in November 2022 that reportedly affected more than 53,000 individuals. Less than two weeks later, at least four lawsuits had been filed against the firm. Now, four mo… Continue reading Family Healthcare notifying patients of November 2022 breach at Brady Martz & Associates

Sébastien Raoult sentenced in federal court; could be out in less than 11 months

Earlier today,  French natural Sébastien Raoult learned his sentence in federal court in Seattle. Raoult, aka “Sezyo,” had been detained in Morocco as he prepared to fly home to France after a vacation. His detention in response to a Red No… Continue reading Sébastien Raoult sentenced in federal court; could be out in less than 11 months

Capital Health acknowledges a cyberattack last month but details are lacking

LockBit3.0 claims to have hit CapitalHealth.org in New Jersey. In a listing posted on their site on January 7, the threat actors write, “We purposely didn’t encrypt this hospital so as not to interfere with patient care. We just stole over … Continue reading Capital Health acknowledges a cyberattack last month but details are lacking

Parathon by JDA e-Health: what we still don’t know about their July ransomware incident

On August 1, DataBreaches noticed that Parathon by JDA e-Health had been listed on the Akira ransomware leak site. Neither Akira nor Parathon responded to DataBreaches’ inquiries at the time, as DataBreaches reported on August 6. On October 30, P… Continue reading Parathon by JDA e-Health: what we still don’t know about their July ransomware incident

Recent attacks on Fred Hutch and Integris: Is attempting to extort patients directly becoming the “new normal?”

DataBreaches previously reported a breach involving Integris Health in Oklahoma. The incident did not involve encryption, but the threat actors were reportedly contacting patients directly and offering to remove their protected health information for a… Continue reading Recent attacks on Fred Hutch and Integris: Is attempting to extort patients directly becoming the “new normal?”

Integris Health notifying patients of hack and warning them not to respond to the hackers

On December 24, Integris Health of Oklahoma started contacting patients about a cyberattack on November 28. The unnamed threat actors did not encrypt any of the health system’s files, but Integris learned that patients were being contacted direct… Continue reading Integris Health notifying patients of hack and warning them not to respond to the hackers