❌

Reading view

There are new articles available, click to refresh the page.

Two Maryland hospitals still dealing with system issues after cyberattack

On September 22, WYPR reported: Luminis Health says it’s making considerable progress on restoring systems at two Maryland hospitals after they were hit by a cyberattack earlier this month. The company said in an online update that its telephone capabilities at Anne Arundel Medical Center and Doctors Community Medical Center in Lanham have been restored...

Source

Ryuk Ransomware Operator Sentenced to 24 Months in Prison

Abinaya reports: An Armenian national extradited from Ukraine to the United States has been sentenced to federal prison for his role in Ryuk ransomware attacks that targeted organizations worldwide, including a company in Oregon. Karen Vardanyan, 35, received a 24-month federal prison sentence followed by 3 years of supervised release, according to the U.S. Attorney’s...

Source

Israeli cyber manager accused of remotely accessing cameras, stealing passwords and infiltrating 26 companies

Amir Kurz recently reported: Three weeks after his arrest, the State Attorney’s Office’s Cyber Department on Thursday filed a major indictment against Michael “Miki” Bar, a 43-year-old hacker from Ashkelon who served as Chief Information Security Officer for the Hamat Group. The group itself has no connection to the charges. According to the indictment, Bar...

Source

Ransomware attack on Kansas county will affect some services

Joseph McCarty reports: A Kansas county’s government says it has been hit by a ransomware attack. Ellis County discovered the attack on parts of its information technology systems Thursday morning. Officials said they “immediately took steps to contain the disruption” by isolating the affected systems and enlisting the help of cybersecurity experts. The county said...

Source

Canada: Nipigon hospital hit by ransomware attack

Mike Stimpson reports: Some patient services may be affected as the general hospital in Nipigon responds to what it describes as a “cyber security incident.” An incident involving ransomware affected information technology systems, Nipigon District Memorial Hospital stated in a post on social media. […] Nipigon Mayor Suzanne Kukko told CFNO’s Al Cresswell “the hospital...

Source

Ransomware group claims attack on Missouri’s Cedar County Memorial Hospital after IT outage

DysruptionHub reports: Cedar County Memorial Hospital in El Dorado Springs, Missouri, shut down its IT networks Aug. 14 after a disruption left its electronic health record, patient portal and internet access unavailable. The outage also disrupted diagnostic imaging. Hospital systems could not transmit images to radiologists, so the emergency department partially diverted trauma and critical...

Source

Ukrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomware

There’s an update to a previously reported case. From the Department of Justice, this press release: Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspiracy to commit wire fraud in connection with a conspiracy to deploy Conti, a ransomware variant that infected the computers of more than 1,000...

Source

“Network outage” disrupts Westfield Public Schools in New Jersey as ransomware group posts samples

Joseph Topping reports: Westfield Public Schools in New Jersey kept classrooms open during a districtwide network outage that disrupted communications and digital instruction throughout the first week of school. The district initially attributed the outage to equipment failure. “We have confirmed that a networking hardware failure caused the disruption across all district schools and offices,”...

Source

FalconFlank Zero-Day Hits CrowdStrike Falcon Sensor (1)

CyberKendra reports: A security researcher known as Chaotic Eclipse has released FalconFlank, a proof-of-concept zero-day that escalates privileges on fully patched Windows machines running CrowdStrike Falcon. The researcher — who also uses the aliases Nightmare-Eclipse, MSNightmare, and INFINITE NIGHTMARE — published working exploit code to GitHub on September 3, 2026, without giving CrowdStrike advance notice. No CVE ID...

Source

Two “Nephrology Associates” suffered cyberattacks. Only one of them has disclosed it.

Sometimes, first impressions are wrong. And in the case of “Nephrology Associates,” DataBreaches mistakenly thought one victim was attacked by two different groups. But no, there are actually two unrelated entities with the same name that suffered attacks this year. And only one of them has disclosed it. The Kansas Incident On March 7, The...

Source

Russian National Indicted For Exploiting Online Platform Used For Freelance Employment And Distributing Malware To Thousands Of Victims

SAN FRANCISCO – A federal grand jury has indicted Searzhudin Tamirlanovich Aktulaev on charges of Conspiracy, Transmission of a Program, Information, Code, and Command to Cause Damage to a Protected Computer, and Aggravated Identity Theft, among other offenses.  Defendant was arrested in Cyprus in May 2025 and has been extradited to the United States.  Yesterday,...

Source

Time’s Up: Ransomware Group Claims 150,000+ Cardiology Patient Records. We’ve Seen the Data.

On August 6, DataBreaches reported that Cardiology Associates of Port Huron (CAPH), a Michigan medical practice with 9 locations, appeared to have been breached by a group called Orova. As reported at the time, the listing included screenshots with personally identifiable and protected health information. Orova’s listing, posted on its leak site on August 4,...

Source

SCOOP: Some Click2Mail customers will soon be receiving notification of a data security incident

On August 27, DataBreaches woke up to a message request on Signal that read, “Click2mail.com checkout with a debit card, website is actively hijacked. Card gets sold to fraudsters. It’s happened twice.” DataBreaches accepted the request, and learned that the customer who contacted us first experienced a problem on June 2, and then again the...

Source

National Kidney Registry allegedly hacked by DireWolf ransomware group

Since its emergence in May 2025, DireWolf has attacked several U.S. healthcare entities, as listed among its more than 100 targets on its dedicated leak site. As early analysts reporting on the group have noted, DireWolf encrypts victims’ files as part of their double-extortion attacks. Their “About” statement describes them as financially motivated: We are...

Source

Inside a Syrian Interrogation Room: The Detainee Files an Infostealer Stole From a Military Police Unit

Hudson Rock’s InfoStealers has an interesting story. From their Executive Summary: In May 2023, an infostealer infected a computer belonging to the Military Police Investigation Section in Suluk, northern Syria – a unit of the Turkish-backed Syrian National Army (SNA). The malware took saved passwords, cookies and a live Telegram session. Then its file-grabber module reached...

Source

Beware the Ransomware Rescuer: Ransom Busters

Justin Timothy reports: The GuidePoint Research and Intelligence Team (GRIT) has responded to several recent ransomware incidents in which victims received an unexpected email from an ostensible third-party entity referring to itself as “Ransom Busters.” In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous....

Source

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics

Tim Starks reports: The ransomware-as-a-service group Medusa has adopted fresh tactics to gain access and added hundreds of victims in a little more than a year, according to an updated U.S. government advisory published Tuesday. The gang is relying on access brokers,compensating them anywhere from $100 to $1 million, with higher prices going to those...

Source

235 GB of PHI and internal documents dumped; Chaos claims it comes from Healthcare Highways

“Chaos” is a Ransomware-as-a-Service (RaaS) group first found online in March, 2025.  On August 5, 2026, they added Healthcare Highways to their dedicated leak site, with a 24-hour countdown clock. Healthcare Highways describes itself as a medical provider network company that offers solutions to businesses and their employees built around high-quality hospital systems, physicians, and...

Source

❌