Ransomware attackers leak stolen Rhode Island private info following hack

Data leak
(Image credit: Shutterstock/dalebor)

  • RIBridges data has been leaked on the Dark Web
  • The ransomware attack took place on December 5
  • Brain Cipher ransomware group has now claimed responsibility for the attack

The ransomware gang involved in the recent attack against the Rhode Island health coverage, human services, and benefit programs website, RIBridges, has started leaking documents from the attack.

The Brain Cipher ransomware group began leaking documents on its data leak site last week, likely in an effort to exert pressure on RIBridges and the State to pay the ransomware fee.

RIBridges was first targeted on December 5 2024, before the state’s vendor Deloitte confirmed the breach on December 10 after being sent a screenshot of internal systems by the attackers, and informed the state that the attackers had successfully gained access to data and had potentially stolen it.

Data on adults and minors leaked

The data stolen in the attack could include names, addresses, dates of birth, Social Security numbers, and certain banking information, and could affect up to 650,000 individuals who used the RIBridges system.

Cybersecurity researcher Connor Goodwolf downloaded the leaked files and provided several screenshots of folders, with some shown to contain tens of gibibytes of data.

“The ransomware group Brain Cipher has released the breach data from the Deloitte RIBridges hack, containing PII of not just adults but minors,” Goodwolf added in a post on X (formerly Twitter). The screenshots from the site also show a statement from the Brain Cipher group stating, “It seems that it was easier to pay and fix everything.”

Rhode Island’s Governor Daniel McKee confirmed that data from the RIBridges system had been leaked online in a statement, “Deloitte informed us that the cybercriminal released some RIBridges files on the dark web. While IT teams are working diligently to analyze the files, the most important thing Rhode Islanders can do is protect their personal information now.”

Rhode Island state officials have recommended that individuals who believe they may have been affected by the ransomware attack should use the free credit monitoring services being provided by the state to freeze and monitor their credit, and also remain vigilant against potential phishing attacks targeting compromised email addresses.

Via Bleeping Computer

You might also like

Benedict Collins
Staff Writer (Security)

Benedict has been writing about security issues for over 7 years, first focusing on geopolitics and international relations while at the University of Buckingham. During this time he studied BA Politics with Journalism, for which he received a second-class honours (upper division), then continuing his studies at a postgraduate level, achieving a distinction in MA Security, Intelligence and Diplomacy. Upon joining TechRadar Pro as a Staff Writer, Benedict transitioned his focus towards cybersecurity, exploring state-sponsored threat actors, malware, social engineering, and national security. Benedict is also an expert on B2B security products, including firewalls, antivirus, endpoint security, and password management.

Read more
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Thousands of Rhode Island citizens have data stolen after social services hit by cyberattack
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major hospital ransomware breach exposed data of 300,000 patients
ransomware avast
The biggest addiction treatment provider in the US says it was hit by data breach
Cl0p ransomware group says it was behind Cleo attacks
Lock on Laptop Screen
Clop ransomware lists Cleo cyberattack victims
A person's fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
Blood donation firm reveals donor personal data stolen in cyberattack
Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 9 (game #1140)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 9 (game #371)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 9 (game #637)
WhatsApp
WhatsApp just made its AI impossible to avoid – but at least you can turn it off