Supply chain
β Supply Chain
Moffitt Cancer Center Third-Party Breach (April 2024)
Primary Source βIncident Details
Medusa Ransomware Group Leaks Data Stolen from American Renal Associates. The Medusa ransomware group has leaked data stolen from American Renal Associates. Moffitt Cancer Center has been affected by a cyberattack on a vendor, American Renal Associates has experienced a ransomware attack involving the theft of more than 37,700 patients’ data. Data breaches have also been reported by Moffitt Cancer Center, Family Health Center, and Zuckerberg San Francisco General Hospital. American Renal Associates (ARA), one of the largest providers of dialysis services in the United States and a provider of care for patients suffering from end-stage renal disease has experienced a Medusa ransomware attack. The ransomware attack has yet to be announced by ARA, but the Medusa ransomware group has leaked data allegedly stolen in the attack. The attack occurred on March 2, 2024, and affected hundreds of computers. Third-party company: Gunster Yoakley and Stewart PA.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Gunster Yoakley and Stewart PA
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2024-04-01 Breach occurred
- 2024-04-08 Publicly disclosed