HHS: Clop ransomware group preying on healthcare sector

Clop ransomware group has reportedly been infecting files that look like medical documents and subsequently requesting medical appointments in hopes of getting victims to open the malicious files, HHS warned in a Jan. 4 analyst note. 

Advertisement

Six things to know about the ransomware group, according to HHS:

  1. Clop operates under a ransomware-as-a-service model.
  2. The group typically targets organizations with an annual revenue of $5 million or higher.
  3. Clop is known to be the successor of CryptoMix ransomware, which is believed to have been developed in Russia.
  4. The group has been infecting files that are disguised to look like medical documents, submitting them to facilities, and then requesting a medical appointment in hopes of the documents being opened and reviewed.
  5. Clop is using this tactic after the group faced difficulties getting victims to pay out on a ransom.
  6. HHS said healthcare organizations should remain vigilant and continue to defend against common attack vectors such as known vulnerabilities, credential abuse and phishing.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.