Ransomware

HIPAA Journal

πŸ“… 2024-06-19 🏒 Acadian Ambulance EMS systems 🦠 Daixin Team ransomware
Primary Source β†—

Incident Details

Acadian Ambulance Service, a Louisiana-based emergency medical services provider, was attacked by the Daixin Team ransomware gang between June 19-21, 2024. The group claimed to have exfiltrated data on approximately 10 million patients and threatened public release unless a $7 million ransom was paid. Acadian negotiated but offered only $173,000 and ultimately did not pay. The breach was reported to HHS OCR as affecting 2,896,985 individuals, with data including names, addresses, Social Security numbers, dates of birth, and detailed medical/patient intake information. Acadian Ambulance is seeking dismissal of a resulting class action lawsuit.

Technical Details

Initial Attack Vector
CWE-284: Improper Access Control
Vendor / Product
Acadian Ambulance EMS systems
Malware Family
Daixin Team ransomware

Timeline

  1. 2024-06-19 Breach occurred
  2. 2024-08-20 Publicly disclosed
  3. 2024-11-01 Customers notified