Concord Orthopaedics Faces Everest Ransomware Threat

Incident Date: Nov 24, 2024

Attack Overview
VICTIM
Concord Orthopaedics
INDUSTRY
Healthcare Services
LOCATION
USA
ATTACKER
Everest
FIRST REPORTED
November 24, 2024

Ransomware Attack on Concord Orthopaedics by Everest Group

Concord Orthopaedics, a leading healthcare provider specializing in orthopaedic and rheumatology care, has fallen victim to a ransomware attack orchestrated by the Everest ransomware group. This cybercriminal organization, known for its double extortion tactics and targeting of critical sectors like healthcare, has threatened to leak sensitive data from Concord Orthopaedics unless ransom demands are met.

Company Profile

Concord Orthopaedics, established in 1974, is a prominent healthcare provider located in Concord, New Hampshire. The organization offers a wide range of orthopaedic specialties, diagnostic services, and operates two dedicated Orthopaedic Surgery Centers. With a team of 27 physicians, 23 physician assistants, and three nurse practitioners, Concord Orthopaedics is the largest private orthopaedic practice in New Hampshire, emphasizing specialized care and patient-centered treatment plans.

Attack Overview

The Everest ransomware group has claimed responsibility for infiltrating Concord Orthopaedics' systems and threatening to release sensitive data within a specified timeframe. The attackers have already shared sample screenshots on their dark web portal, indicating the potential exposure of medical records, personal data of patients from 2018, and over 30,000 identity documents. The company's website includes instructions for contacting the attackers to prevent data leakage.

Ransomware Group Details

The Everest ransomware group, active since December 2020, has evolved its tactics to target healthcare organizations, aerospace companies, and government entities. Notably, Everest has transitioned into an Initial Access Broker role, selling unauthorized network access to other ransomware groups. The group's operational tactics include lateral movement, credential access, data exfiltration, and double extortion, increasing pressure on victims to comply with ransom demands.

Company Vulnerabilities

Concord Orthopaedics' prominence in the healthcare sector, extensive patient data, and specialized services make it an attractive target for threat actors like the Everest ransomware group. The organization's commitment to quality care and patient satisfaction, while commendable, may also pose vulnerabilities in terms of data security and cyber resilience.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.