Ransomware
HIPAA Journal / CM Alliance / The Record
Primary Source βIncident Details
Rhysida ransomware attacked Lurie Children’s Hospital of Chicago (pediatric hospital) Jan 26-31 2024. Patient-facing systems offline for ~3.5 months. 791,784 individuals notified of PHI exposure including names, DOBs, SSNs, medical records, prescriptions, health plan data. $3.4M ransom demanded; hospital refused to pay. Rhysida claimed to have sold data. Class action lawsuits filed. Rhysida also attacked British Library (Oct 2023, 600GB stolen, ~$7.5-8.7M recovery cost) and Prospect Medical Holdings.
Technical Details
- Initial Attack Vector
- CWE-1391: Use of Weak Credentials (exact vector not publicly disclosed)
- Vendor / Product
- Lurie Children's Hospital of Chicago IT systems
- Malware Family
- Rhysida
Timeline
- 2024-01-26 Breach occurred
- 2024-02-01 Publicly disclosed
- 2024-05-01 Customers notified