Healthcare Sector Under Siege: The Impact of Ransomware on Plastic Surgery Practices
Ransomware Attack on Dr. Lincoln Graça Neto's Clinic by Qiulong Group
Company Profile
Dr. Lincoln Graça Neto, a prominent plastic surgeon based in Curitiba, Brazil, operates a private practice specializing in both humanitarian and cosmetic plastic surgery. His clinic is renowned for providing natural-looking and enduring results, leveraging advanced surgical techniques. Dr. Graça Neto holds an MD, MSc, and PhD, and has contributed to the field with research on innovative breast implant procedures. His professional standing includes former leadership roles in significant plastic surgery training and international plastic surgery organizations.
Ransomware Attack Details
The Qiulong ransomware group, known for its activities primarily in Latin America, has recently targeted Neto's clinic. The attack resulted in the encryption of sensitive data, including nude images of patients, personal data, accounting records, financial documents, contact information, and non-disclosure agreements. This data breach poses significant privacy and security risks to the patients and the clinic's operations.
Ransomware Group Profile: Qiulong
The Qiulong group employs sophisticated tactics similar to those of the Hive and Nokayawa ransomware families. They typically gain access through known valid accounts, exposed Remote Desktop Protocol (RDP) servers, and vulnerabilities in FortiOS. Their modus operandi includes using tools like AdFind for gathering information and distributing malicious executables via internal network mechanisms. The ".play" file extension is commonly used for encrypted files in their attacks.
Vulnerabilities and Industry Impact
The clinic, like many in the healthcare sector, handles sensitive personal and medical information, making it a high-value target for cybercriminals. The combination of high-stakes data and potentially insufficient cybersecurity measures can make healthcare institutions particularly vulnerable to ransomware attacks. The breach not only threatens patient confidentiality but also the clinic's reputation and operational continuity.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!