Supply chain
β Supply Chain
Surgery Center of Mid Florida Third-Party Breach (August 2024)
Primary Source βIncident Details
Six Healthcare Providers Added to Ransomware Data Leak Sites. Recent reports by Rapid7 and Guidepoint Security indicate the number of active ransomware groups has increased in 2024, as has the number of attacks. The Healthcare providers in Delaware, Florida, New York, Rhode Island, and Texas have recently been added to the data leak sites of ransomware groups: Bayhealth, The Surgery Center of Mid Florida, Gramercy Surgery Center, Betances Health Center, Community Care Alliance, and Brookshire Dental. The Surgery Center of Mid Florida has recently alerted patients about a network encryption event (ransomware). The attack was detected on or around February 21, 2024, when unusual network activity was observed. The investigation confirmed file encryption, with the initial hacking occurring at its IT vendor. The hackers then used the connection with the IT vendor to launch an attack on its network.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Third-party vendor
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2024-08-01 Breach occurred
- 2024-08-12 Publicly disclosed