Hospitals among top targets in $34M crypto ransomware spree: Report

Advertisement

A ransomware group known as Embargo has extorted millions of dollars from victims in the U.S., including hospitals, according to research from blockchain intelligence firm TRM Labs.

Here are six things to know from TRM Labs’ report:

  1. Embargo, which operates under a ransomware-as-a-service model, emerged in April 2024 and has since been tied to an estimated $34.2 million in cryptocurrency transactions, TRM Labs said in an Aug. 8 news release.

  2. Most victims are in the healthcare, business services and manufacturing sectors, with some ransom demands reaching $1.3 million.

  3. Notable U.S. victims include American Associated Pharmacies, Memorial Hospital and Manor in Bainbridge, Ga., and Weiser Memorial Hospital in Weiser, Idaho. The group disproportionately targets U.S. organizations, TRM Labs said, likely because they are seen as more able to pay large ransoms.

  4. Embargo may be a rebranded version of the now-defunct BlackCat gang, according to the report.

  5. The group launders ransom payments through intermediary wallets, high-risk cryptocurrency exchanges and sanctioned platforms, including Cryptex.net, TRM Labs said.

  6. Healthcare organizations are particularly attractive targets because operational disruptions can affect patient care, according to TRM Labs.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement