The threat group claimed responsibility on Dec. 7 and posted nine file samples of data on the dark web it says was stolen during the attack. The files include medical records, surgical authorizations and financial records from the hospital.
One of the documents appears to reveal the California Health Department bank account number that Tri-City used to transfer funds.
Inc. Ransomware is a “multi-extortion operation,” according to the SentinelOne, a cybersecurity company, and has targeted healthcare organizations as well as education and government agencies. The group typically gains access to IT systems through phishing emails and then places ransom notes in folders with encrypted items. It also prints out the ransom note, which Tri-City reportedly experienced.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.