Cyber Intelligence

Linkedin
  • News
    • Aerospace
    • Apple
    • Arrest
    • Automotive
    • Big Tech
    • Breaking News
    • Business Email Compromise
    • China
    • Chip Technology
    • Cryptocurrency
    • Cyber Budget
    • Cyber Espionage
    • Cyber M&A
    • cybercrime
    • Data Leak
    • deepfake
    • Energy Sector
    • Ethiopia
    • Finance
    • France
    • Geopolitics
    • Government
    • Hacktivism
    • Healthcare
    • Human Error
    • Investment Scam
    • Iran
    • Israel Conflict
    • Malicious Bots
    • Malware
    • North Korea
    • Norton
    • One Minute Roundup
    • ransomware
    • SEC
    • SMB
    • Social Media
    • Sri Lanka
    • Taiwan
    • VPN
    • Wire Fraud
    • Workforce Cyber
  • Analysis
  • Expert Opinions
  • Resources
    • Conferences
    • Glossary of terms
    • Awards
    • Ecosystem map
Reading: Healthcare sector attacks on the rise
Share
Cyber IntelligenceCyber Intelligence
Aa
  • News
  • Analysis
  • Expert Opinions
  • Resources
Search
  • News
    • Aerospace
    • Apple
    • Arrest
    • Automotive
    • Big Tech
    • Breaking News
    • Business Email Compromise
    • China
    • Chip Technology
    • Cryptocurrency
    • Cyber Budget
    • Cyber Espionage
    • Cyber M&A
    • cybercrime
    • Data Leak
    • deepfake
    • Energy Sector
    • Ethiopia
    • Finance
    • France
    • Geopolitics
    • Government
    • Hacktivism
    • Healthcare
    • Human Error
    • Investment Scam
    • Iran
    • Israel Conflict
    • Malicious Bots
    • Malware
    • North Korea
    • Norton
    • One Minute Roundup
    • ransomware
    • SEC
    • SMB
    • Social Media
    • Sri Lanka
    • Taiwan
    • VPN
    • Wire Fraud
    • Workforce Cyber
  • Analysis
  • Expert Opinions
  • Resources
    • Conferences
    • Glossary of terms
    • Awards
    • Ecosystem map

Cyber Intelligence

Linkedin
  • News
    • Aerospace
    • Apple
    • Arrest
    • Automotive
    • Big Tech
    • Breaking News
    • Business Email Compromise
    • China
    • Chip Technology
    • Cryptocurrency
    • Cyber Budget
    • Cyber Espionage
    • Cyber M&A
    • cybercrime
    • Data Leak
    • deepfake
    • Energy Sector
    • Ethiopia
    • Finance
    • France
    • Geopolitics
    • Government
    • Hacktivism
    • Healthcare
    • Human Error
    • Investment Scam
    • Iran
    • Israel Conflict
    • Malicious Bots
    • Malware
    • North Korea
    • Norton
    • One Minute Roundup
    • ransomware
    • SEC
    • SMB
    • Social Media
    • Sri Lanka
    • Taiwan
    • VPN
    • Wire Fraud
    • Workforce Cyber
  • Analysis
  • Expert Opinions
  • Resources
    • Conferences
    • Glossary of terms
    • Awards
    • Ecosystem map
Reading: Healthcare sector attacks on the rise
Share
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
AnalysisHealthcare

Healthcare sector attacks on the rise

Hildegard Johnson
August 30, 2023 at 7:32 PM
By Hildegard Johnson Hildegard Johnson
Share
SHARE

The healthcare sector is coming under increasingly severe pressure from cyber-attacks. On the heels of news earlier last week that the infamous Lazarus Group is launching a new campaign targeting internet backbone infrastructure and healthcare facilities in the US and Europe comes news of a major attack by the Rhysida ransomware group on Los Angeles-based Prospect Medical Holdings.

Earlier this month, Prospect Medical Holdings was forced to take down its systems following major cyber-attacks at hospitals and other medical facilities across four states. Rhysida has now claimed responsibility for the theft of a 1.3 terabyte SQL database containing 500,000 Social Security numbers, corporate documents, and patient records and is now threatening to sell Prospect Medical’s allegedly stolen data for 50 Bitcoins (around $1.3 million) if Prospect Medical Holdings refuses to pay up.

The trillion-dollar US healthcare sector’s ever-expanding array of internet-connected medical devices combined with its legacy IT systems make it an attractive target for hackers. But not all attackers represent an equally serious threat. Fast-growing ransomware newcomer, the Rhysida group, appears to be motivated solely by opportunistic financial gain. The Lazarus Group, on the other hand, has more sinister motives. State-sponsored by North Korea, the aim of the group is twofold; profits from such gangs go to fund North Korea’s growing nuclear arsenal while the threat actors simultaneously target crucial facilities as part of a planned coordinated potential future attack on US infrastructure. 

The Lazarus group’s latest campaign was first identified by researchers at Cisco’s threat intelligence arm, Cisco Talos. On the day Cisco Talos’ analysis was published, the FBI also issued a warning to cryptocurrency firms regarding a sudden surge in blockchain activity linked to the theft of hundreds of millions in digital currency attributed to the Lazarus Group.

Rhysida’s claiming responsibility for the attack on Prospect Medical also follows a warning earlier in August by the Department of Health and Human Services (HHS) that Rhysida is behind many recent attacks on healthcare organizations. According to HHS, Rhysida is a new ransomware group that has been active since May 2023. HHS reports that  Rhysida’s usual modus operandi is to deliver ransomware via phishing attacks to breach a target organization’s networks. The group then threatens to publicly expose the exfiltrated data if the victim refuses to pay Rhysida’s ransom demand.

According to cybersecurity firm Cloudflare’s 2023 Phishing Threats Report, published earlier this year, a growing number of attacks now use phishing attacks to impersonate someone else’s identity. It is the third-most prevalent email threat category; Cloudflare reports identity deception in 14.2% of detections from May 2, 2022, to May 2, 2023, a jump from 10.3% from the previous year and that this type of attack frequently comprises brand impersonation and business email compromise (BEC).

One explanation for the marked rise in attacks using identity and brand deception is cybercriminals’ increasing use of artificial intelligence platforms such as ChatGPT and its Dark-Web equivalent FraudGPT to craft well-written and plausible-sounding spoof emails. Previously, spoof emails were frequently easily identifiable by poor grammar and misspellings. The new AI platforms can not only write well-crafted personalized emails but also trawl social networks in order to draft an email with sufficient personal data to convince the recipient that it comes from a trusted supplier or colleague.

TAGGED: cisco talos, cloudflare, department of health and human services, generative ai, healthcare, lazarus group, phishing, prospect medical holdings, Ransomware, rhysida
Hildegard Johnson September 11, 2023 August 30, 2023
Share This Article
Twitter LinkedIn Email Copy Link Print
Previous Article The Daily Decrypt - One Minute Roundup FBI nails Qakbot offender – August 30th
Next Article The Daily Decrypt - One Minute Roundup New Android malware, MMRat, can unlock phones – August 31st
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Editor's Pick

You Might Also Like

NewsOne Minute RoundupOne Minute Roundup

Geopolitical Tensions are Changing the Cybersecurity Landscape – June 13th

Political tensions are prompting nations to re-strategize cybersecurity. Countries that once sought international cooperation and joint strategies are now prioritizing domestic cyber capacities and national interests as a result of geopolitical instabilities.

June 13, 2025
cybercrimeNewsransomwareRussia

Teenage hackers run rings around cyber-defenses

The recent UK retail cyberattacks that impacted Marks & Spencer and the Co-Op supermarket chain are only the tip of a very large iceberg that now threatens organizations on both sides of the Atlantic. Although media reports have attributed the attacks to a group named “Scattered Spider,” the actual threat is far bigger. For a start, there is no criminal group that actually calls itself “Scattered Spider”, which is just a made-up name attributed by cybersecurity researchers. These attacks and many others in the US and the UK are now known to be the work of a vast sprawling network of hackers, some as young as 14, spread across the US and the UK. They call themselves “the Community”, or “the Com” for short, and are essentially a vast teenage subculture of criminal hackers.

June 10, 2025
cybercrimeData LeakGovernmentNews

White House phone hack rings alarm bells

An attempt to impersonate White House Chief of Staff Susie Wiles is currently being investigated by US federal agencies. The incident highlights the ongoing dangers posed by key individuals using their personal phones to store the phone numbers of important contacts, now that voice cloning enables cybercriminals to mimic anyone’s voice with ease.

June 6, 2025
NewsOne Minute Roundup

Deepfake Phishing Targets Trump’s Chief of Staff – May 30th

In today's daily roundup - Deepfake Phishing Targets Trump’s Chief of Staff, ConnectWise Breached by Suspected Nation-State Actor, and Unbound Security Raises $4M Seed Funding.

May 30, 2025

Cyber Intelligence

We provide in-depth analysis, breaking news, and interviews with some of the leading minds in cybersecurity and distill critical insights that matter to our readers. Daily.

Linkedin

Category

  • Cybercrime
  • News

Quick Links

  • News
    • Aerospace
    • Apple
    • Arrest
    • Automotive
    • Big Tech
    • Breaking News
    • Business Email Compromise
    • China
    • Chip Technology
    • Cryptocurrency
    • Cyber Budget
    • Cyber Espionage
    • Cyber M&A
    • cybercrime
    • Data Leak
    • deepfake
    • Energy Sector
    • Ethiopia
    • Finance
    • France
    • Geopolitics
    • Government
    • Hacktivism
    • Healthcare
    • Human Error
    • Investment Scam
    • Iran
    • Israel Conflict
    • Malicious Bots
    • Malware
    • North Korea
    • Norton
    • One Minute Roundup
    • ransomware
    • SEC
    • SMB
    • Social Media
    • Sri Lanka
    • Taiwan
    • VPN
    • Wire Fraud
    • Workforce Cyber
  • Analysis
  • Expert Opinions
  • Resources
    • Conferences
    • Glossary of terms
    • Awards
    • Ecosystem map

© 2023 Cyberintel.media

Welcome Back!

Sign in to your account

Lost your password?