Asaro Dental Aesthetics Hit by Everest Ransomware Attack
Ransomware Attack on Asaro Dental Aesthetics by Everest Group
On November 13, Asaro Dental Aesthetics, a prominent dental practice in West Hollywood, California, became the latest victim of a ransomware attack by the notorious Everest group. This incident highlights the persistent vulnerabilities in the healthcare sector, where sensitive patient data remains a lucrative target for cybercriminals.
About Asaro Dental Aesthetics
Asaro Dental Aesthetics, led by Dr. Matthew Asaro, is renowned for its focus on aesthetic dentistry, offering services such as veneers, Invisalign, and dental implants. The practice is distinguished by its use of high-quality materials and advanced technology, emphasizing minimally invasive techniques and patient comfort. Despite its reputation for excellence, the practice's reliance on digital systems for patient records and treatment planning may have made it susceptible to cyber threats.
Details of the Attack
The ransomware attack orchestrated by the Everest group resulted in the unauthorized extraction of sensitive medical and personal data from approximately 3,800 patients. The attackers have released screenshots of the stolen data as proof of the breach, although the full extent of the data leak remains unclear. This breach underscores the critical need for enhanced cybersecurity measures in healthcare practices, particularly those handling sensitive patient information.
Profile of the Everest Ransomware Group
The Everest ransomware group, active since December 2020, is known for its double extortion tactics, encrypting data while threatening to leak it. Recently, the group has shifted its focus towards the healthcare sector, exploiting vulnerabilities in medical facilities. Everest distinguishes itself by acting as an Initial Access Broker, selling unauthorized access to networks to other cybercriminals. Their sophisticated tactics include lateral movement within networks and data exfiltration using tools like WinRAR and Cobalt Strike.
Potential Vulnerabilities and Penetration Methods
Asaro Dental Aesthetics, like many healthcare providers, may have been vulnerable due to its digital infrastructure, which, if inadequately protected, can be exploited by threat actors. The Everest group likely penetrated the practice's systems through compromised user accounts or vulnerabilities in remote access protocols, allowing them to move laterally and extract sensitive data. This incident serves as a stark reminder of the importance of cybersecurity vigilance in protecting patient information.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!