Supply chain β›“ Supply Chain

Moffitt Cancer Center Third-Party Breach (April 2024)

πŸ“… 2024-04-01 🏒 Gunster Yoakley and Stewart PA
Primary Source β†—

Incident Details

Medusa Ransomware Group Leaks Data Stolen from American Renal Associates. The Medusa ransomware group has leaked data stolen from American Renal Associates. Moffitt Cancer Center has been affected by a cyberattack on a vendor, American Renal Associates has experienced a ransomware attack involving the theft of more than 37,700 patients’ data. Data breaches have also been reported by Moffitt Cancer Center, Family Health Center, and Zuckerberg San Francisco General Hospital. American Renal Associates (ARA), one of the largest providers of dialysis services in the United States and a provider of care for patients suffering from end-stage renal disease has experienced a Medusa ransomware attack. The ransomware attack has yet to be announced by ARA, but the Medusa ransomware group has leaked data allegedly stolen in the attack. The attack occurred on March 2, 2024, and affected hundreds of computers. Third-party company: Gunster Yoakley and Stewart PA.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Gunster Yoakley and Stewart PA
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-04-01 Breach occurred
  2. 2024-04-08 Publicly disclosed