FBI warns US hospitals they may be hit by BlackCat ransomware, so be on their guard

ID theft
Image credit: Pixabay (Image credit: Future)

The Cybersecurity and Infrastructure Security Agency (CISA), together with the FBI and the US Department of Health and Human Services (HHS) is warning hospitals and other healthcare organizations in the country to be wary of ALPHV (BlackCat).

Earlier this week, the security agencies updated their advisory that helps organizations combat ransomware, saying that since mid-December 2023 the ALPHV ransomware operators (also known as BlackCat) have mostly been targeting firms in the healthcare sector.

In the last three months, almost 70 organizations have had their data leak on the dark web, most of which were hospitals and healthcare firms.

Change Healthcare attack a warning

The advisory says that the threat actors are improving their communications with the victims, by creating custom emails to notify of the initial compromise. 

Furthermore, the group has recently upgraded the encryption software to the 2.0 Sphynx upgrade, which provided additional features to affiliates, including better defense evasion and additional tooling.

“This ALPHV BlackCat update has the capability to encrypt both Windows and Linux devices, and VMWare instances. ALPHV BlackCat affiliates have extensive networks and experience with ransomware and data extortion operations,” the advisory reads.

Hospitals are urged to take necessary mitigation measures, to reduce the chances of falling prey to ransomware attacks.

Earlier this month, US health tech giant Change Healthcare suffered a ransomware attack, which was later confirmed to have originated from BlackCat.

The company recently posted a short announcement on its status update website, saying some applications were unavailable due to a “cyber security issue”. The incident forced parts of the company’s infrastructure offline, and some login pages were unavailable, leaving some users unable to access their prescriptions. 

TechCrunch disclosed that the attack was indeed ransomware, undertaken by ALPHV (BlackCat), citing a “healthcare executive with knowledge of the incident, who was on the call briefed by the company’s executives."

Next to LockBit and Cl0p, BlackCat is one of the world’s most prolific ransomware operators.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
data recovery
Ghost ransomware has hit firms in over 70 countries, FBI and CISA warn
security
Ransomware gangs allegedly hit two major US healthcare firms, 300,000 patients have data stolen
A doctor holding a tablet showing holograms of a skeleton, DNA, and other medical diagrams.
Chinese hacking group hijacks hospital computers by spoofing legitimate medical software
Code Skull
US government warns Medusa ransomware has hit hundreds of critical infrastructure targets
Ransomware
Healthcare firms targeted by all-new ransomware strain
healthcare
US government wants to toughen up cybersecurity rules for healthcare organizations
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)