Authorities Issue Joint Advisory on RansomHub Ransomware

RansomHub has impacted at least 210 organizations across critical infrastructure sectors, including healthcare.

By Jeff Wardon, Jr., Assistant Editor


The FBI, Cybersecurity and Infrastructure Security Agency (CISA), Multi-State Information Sharing and Analysis Center (MS-ISAC) and HHS have issued a joint advisory detailing the tactics and indicators of compromise (IOCs) associated with the RansomHub ransomware.  

The advisory says this ransomware-as-a-service variant has gained prominence since its launch in February 2024, particularly by attracting affiliates from other major ransomware groups. RansomHub has impacted at least 210 organizations across critical infrastructure sectors, including healthcare, water and wastewater, IT and government services. 

Affiliates of RansomHub employ a double-extortion model, where they both encrypt systems and exfiltrate data to pressure victims into paying ransoms. The exfiltration methods vary depending on the affiliate involved, according to the advisory. 

Related: Lessons to Learn from the Ascension Ransomware Attack

Ransomware is a serious cyber threat to healthcare organizations, since important and critical data can be rendered inaccessible to those who need it. Many healthcare organizations, such as Ascension, have been affected by ransomware attacks over the past few years.  

Cyberattacks in general don’t show much sign of dying down either, as Healthcare Facilities Today has reported on at least 30 different cyber incidents in the first half 2024 alone. However, this doesn’t mean the situation is hopeless, as healthcare organizations can implement policies and practices to protect themselves. 

In the advisory, CISA recommends taking these three steps to mitigate cyber threats from ransomware: 

  1. Update operating systems, software and firmware as soon as the updates are rolled out. 
  2. Require phishing-resistant multifactor authentication (MFA) for as many services as possible. 
  3. Train staff to recognize and report phishing attempts. 

Jeff Wardon, Jr., is the assistant editor for the facilities market. 



September 6, 2024


Topic Area: Information Technology , Security


Recent Posts

Communication Proves to Be Essential Task During Design Phase

Projects go over more smoothly when people are transparent and communicating openly.


Northwest Healthcare Acquires Carbon Health Urgent Care Centers in Arizona

With this acquisition, Northwest Healthcare has more than 80 sites of care.


Dry-Surface Biofilms: Challenges and Strategies

Environmental services managers might not be using the right disinfectant in their cleaning operations.


The Springs at The Waterfront Senior Living Community Officially Completed

The new twelve-story, 360,000-sqaure-foot, 250-unit community is designed as an optimum environment for the health and well-being of residents and staff.


Intelligent Hospitals: Leveraging Data to Future-Proof Operations

Facilities have an opportunity to integrate smart technology to streamline operations, automate processes and boost patient experience without sacrificing human touch.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

 
 
 
 

Healthcare Facilities Today membership includes free email newsletters from our facility-industry brands.

Facebook   Twitter   LinkedIn   Posts

Copyright © 2023 TradePress. All rights reserved.