BianLian Ransomware Targets Physicians Primary Care SWFL

Incident Date: Dec 10, 2024

Attack Overview
VICTIM
Physicians' Primary Care of Southwest Florida
INDUSTRY
Healthcare Services
LOCATION
USA
ATTACKER
Bianlian
FIRST REPORTED
December 10, 2024

BianLian Ransomware Attack on Physicians' Primary Care of Southwest Florida

Physicians' Primary Care of Southwest Florida (PPC), a leading healthcare provider in the region, has fallen victim to a ransomware attack orchestrated by the notorious BianLian group. This incident underscores the vulnerabilities faced by healthcare organizations in the digital age.

About Physicians' Primary Care of Southwest Florida

Established in 1996, PPC is the largest independent multi-specialty practice in Southwest Florida, with offices in Fort Myers, Cape Coral, Estero, and Lehigh Acres. The organization is physician-owned, emphasizing a patient-centered approach across specialties such as family practice, internal medicine, and pediatrics. With approximately 63 employees and an annual revenue of $15.3 million, PPC is a significant player in the healthcare sector, known for its commitment to quality care and community involvement.

Details of the Ransomware Attack

The BianLian ransomware group claims to have exfiltrated 1.8 terabytes of sensitive data from PPC, including medical records, contracts, and financial information. The breach reportedly began around September 15, 2024, with PPC becoming aware of unauthorized access by September 17. Despite being informed of the breach, the organization allegedly failed to secure its network promptly. On November 14, PPC issued a formal notification, offering credit monitoring services to individuals whose sensitive information may have been compromised.

Profile of the BianLian Ransomware Group

BianLian has emerged as a formidable threat since mid-2022, targeting critical infrastructure sectors, including healthcare. The group is known for its sophisticated tactics, primarily gaining access through compromised Remote Desktop Protocol credentials and exploiting vulnerabilities like ProxyShell. BianLian distinguishes itself by focusing on exfiltration-based extortion, threatening to release stolen data without encrypting victims' systems. This approach allows them to maintain pressure on organizations while minimizing operational disruptions.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.