Concord Orthopaedics Faces Everest Ransomware Threat
Ransomware Attack on Concord Orthopaedics by Everest Group
Concord Orthopaedics, a leading healthcare provider specializing in orthopaedic and rheumatology care, has fallen victim to a ransomware attack orchestrated by the Everest ransomware group. This cybercriminal organization, known for its double extortion tactics and targeting of critical sectors like healthcare, has threatened to leak sensitive data from Concord Orthopaedics unless ransom demands are met.
Company Profile
Concord Orthopaedics, established in 1974, is a prominent healthcare provider located in Concord, New Hampshire. The organization offers a wide range of orthopaedic specialties, diagnostic services, and operates two dedicated Orthopaedic Surgery Centers. With a team of 27 physicians, 23 physician assistants, and three nurse practitioners, Concord Orthopaedics is the largest private orthopaedic practice in New Hampshire, emphasizing specialized care and patient-centered treatment plans.
Attack Overview
The Everest ransomware group has claimed responsibility for infiltrating Concord Orthopaedics' systems and threatening to release sensitive data within a specified timeframe. The attackers have already shared sample screenshots on their dark web portal, indicating the potential exposure of medical records, personal data of patients from 2018, and over 30,000 identity documents. The company's website includes instructions for contacting the attackers to prevent data leakage.
Ransomware Group Details
The Everest ransomware group, active since December 2020, has evolved its tactics to target healthcare organizations, aerospace companies, and government entities. Notably, Everest has transitioned into an Initial Access Broker role, selling unauthorized network access to other ransomware groups. The group's operational tactics include lateral movement, credential access, data exfiltration, and double extortion, increasing pressure on victims to comply with ransom demands.
Company Vulnerabilities
Concord Orthopaedics' prominence in the healthcare sector, extensive patient data, and specialized services make it an attractive target for threat actors like the Everest ransomware group. The organization's commitment to quality care and patient satisfaction, while commendable, may also pose vulnerabilities in terms of data security and cyber resilience.
Sources
- Halcyon AI - Everest Ransomware Hits ArcTrade
- HIPAA Journal - Everest Ransomware Warning Healthcare
- Becker's Hospital Review - Everest Ransomware Group Shifts Focus to Healthcare
- AHA - HHS Alerts Health Sector on Cyberthreat Everest Ransomware Group
- BankInfoSecurity - US Authorities Warn Health Sector of Everest Gang Threats
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!