Another Healthcare Organization Hit By Ransomware

Female healthcare staff working on a mobile device.
Female healthcare staff working on a mobile device.

Universal Health Services Hit With Massive Ransomware Attack

UHS has confirmed that the “IT Network across Universal Health Services (UHS) facilities is currently offline due to an on-going IT security issue.” 

Universal Health Services is a Fortune 500 hospital and healthcare services provider, has reportedly shut down all systems at healthcare facilities across the US after a cyber-attack hit its network early Sunday morning. UHS provides healthcare services to approximately 3.5 million patients each year.  

According to employees, the ransomware attack took place between Saturday and Sunday around 2 am central time.  Employee’s said computers rebooted and then showed a ransom note on the screen around that time.  IT staff immediately shut computers down and asked personnel to keep systems offline.  

Ransomware is not new and attacks against the healthcare industry have continued to rise in 2020.  Healthcare organizations are in the top 5 industries targeted by cybercriminals since PHI (Patient Health Information) is worth more on the black market.  Employees from UHS have been posting claims of how this incident was caused on social networking website Reddit.  One thread stated the incident was caused by a ransomware strain named Ryuk but could not provide evidence to support their claim. 

Ryuk is a type of crypto-ransomware that uses encryption to block access to a system, device or file until a ransom is paid. Ryuk is often dropped on a system by other malware, most notably Trickbot. Ryuk is difficult to detect as it’s often spread via other malware dropping into already existing infected systems.  

Ryuk ransomware is linked to a Russian cybercrime group known as Wizard Spider according to Security firm Crowdstrike.  Ryuk’s operations are known to go “big game hunting: and have previously targeted large organizations including the US Coast Guard.   

Instituting behavioral monitoring tools like Endpoint Detection and Response and a vulnerability management program is a step towards being more cyber secure. To learn more about why you need more than Antivirus to protect your networks, watch our on-demand webinar here. Or, if you’re ready to reduce your risk, schedule a 15-minute consultation with one of our healthcare experts. 

Jerome Smith

Jerome Smith is the Director of Cybersecurity Engineering with over 17 years’ experience in enterprise Information Technology Engineering and Cybersecurity; a dedicated advocate for the effective and secure use of technology in business. Responsible for cybersecurity engineering for Corsica Technologies including Cybersecurity offering Implementation, integration, and development.  Certifications: VMware VCP-DV and VCP-NV, Nutanix NPP, Cisco CMNA, Fortinet NSE 3, Accolades: VMware vExpert Award 2015-2018

LinkedIn

Corsica Technologies
Corsica Technologies is an MSP specializing in cybersecurity solutions, managed IT services, digital transformation, and data integration. Corsica provides solutions for midmarket businesses including network monitoring, data protection, incident response, and IT support. Corsica offers unmetered technology services for fully managed or co-managed teams to address all technology needs under a one-flat monthly fee. 

Related Cybersecurity and IT Reads

vCISO services - Corsica Technologies
Consulting
Ross Filipek

vCISO Services: Staying Secure for Less

In this article: What is a vCISO? vCISO vs CISO Why choose a vCISO? What to look for vCISO pricing How to hire a vCISO 💡Free vCISO Pricing Calculator Access the Calculator The average cost of a data breach is

Read more
M&A consulting - Corsica Technologies
Consulting
Garrett Wiesenberg

Streamlining the M&A Process with Expert Consulting

Mergers and acquisitions are some of the most stressful processes in the business world. The stakes are high, and there are many risks alongside incredible opportunities. How do you navigate the waters of M&A? Consulting services are a huge help.

Read more

Sign Up For Our Newsletter

Stay up-to-date on the Managed Services and Cybersecurity landscape, and be the first to find out about events and special offers.

Ready to talk to an expert?

We’ll respond within 1 business day, or you can grab time on our calendar.