hiveleak attacks Sigmund Software

Incident Date: Sep 20, 2022

Attack Overview
VICTIM
Sigmund Software
INDUSTRY
Healthcare Services
LOCATION
USA
ATTACKER
Hiveleak
FIRST REPORTED
September 20, 2022

Sigmund Software Suffers Ransomware Attack, Exposing Sensitive Data

Overview of the Incident

Sigmund Software, a prominent provider of electronic health record software for healthcare providers, fell victim to a ransomware attack orchestrated by the group known as HiveLeak. This cyber assault, executed on September 9, 2022, led to the unauthorized disclosure and potential theft of sensitive personal identifiable information (PII) of both current and former employees.

Established in 2004 and based in Danbury, Connecticut, Sigmund Software employs over 50 individuals. The company is renowned for its AURA platform, a signature electronic health record system designed specifically for behavioral health organizations.

The Growing Threat of Ransomware in Healthcare

The incident at Sigmund Software is indicative of a broader, more alarming trend of increasing ransomware attacks targeting the healthcare sector. These cyber attacks are not limited to large hospitals but also affect small practices and clinics, compromising patient safety and privacy. The breach at Sigmund Software involved the exposure of critical information, including names and Social Security numbers, underscoring the severity of the threat.

Response and Recommendations

In the wake of the breach, Sigmund Software initiated a series of steps to mitigate the impact on affected individuals. Starting October 20, 2022, the company began the process of notifying potentially impacted parties. It also provided guidance on protective measures, including the importance of reviewing the breach notice, enrolling in a complimentary credit monitoring service offered by Sigmund Software, updating passwords and security questions, monitoring account statements and credit reports for irregularities, and placing a temporary fraud alert with credit bureaus.

This incident serves as a stark reminder of the critical need for healthcare providers to adopt stringent cybersecurity measures. Protecting sensitive patient data against cyber threats is not just a regulatory requirement but a moral obligation to ensure the privacy and security of personal information.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.