Ransomware

Integris Health data breach β€” direct patient extortion (2.4 million)

πŸ“… 2023-11-28 🏒 Integris Health (Oklahoma hospital system)
Primary Source β†—

Incident Details

Attackers gained access to Integris Health’s network on 28 November 2023. On 24 December 2023, Integris discovered that patients were being directly contacted by the cybercriminal group and offered to pay $3 to view their stolen data or $50 to have it deleted, with a deadline of 5 January 2024. HHS OCR notified February 2024 of 2,385,646 individuals affected. Stolen data included names, contact information, dates of birth, demographic information, and SSNs. $30 million class action settlement reached. Novel tactic of directly extorting individual patients rather than only the breached organisation.

Technical Details

Initial Attack Vector
unknown
Vendor / Product
Integris Health (Oklahoma hospital system)

Timeline

  1. 2023-11-28 Breach occurred
  2. 2023-12-24 Publicly disclosed
  3. 2023-12-24 Customers notified