Omint Faces Ransomware Threat from SafePay Group

Incident Date: Nov 19, 2024

Attack Overview
VICTIM
OMINT
INDUSTRY
Healthcare Services
LOCATION
Argentina
ATTACKER
SafePay
FIRST REPORTED
November 19, 2024

Ransomware Attack on Omint: SafePay Strikes a Leading Argentine Healthcare Provider

Omint, a prominent healthcare provider in Argentina, has become the latest victim of a ransomware attack orchestrated by the SafePay group. The attack, which occurred on November 21, 2024, has raised significant concerns about the security of healthcare data and the vulnerabilities of digital transformation in the sector.

About Omint

Established in 1967, Omint is one of Argentina's top five private healthcare companies, offering a comprehensive range of medical services, health plans, and life insurance. The company operates several hospitals in Buenos Aires and has expanded its services to Brazil. Omint is known for its commitment to personalized care and high-quality medical services, supported by a digital infrastructure that includes the Digital Care Platform (PAD). This platform allows users to manage health plans and access medical consultations online, reflecting Omint's focus on enhancing customer satisfaction through technology.

Attack Overview

The ransomware attack on Omint was claimed by SafePay, a group known for its ransomware-as-a-service operations. While the exact size of the data leak remains undisclosed, the attack highlights the vulnerabilities inherent in digital healthcare systems. Omint's extensive use of digital platforms, while beneficial for user experience, may have exposed it to cyber threats, particularly if security measures were not adequately implemented.

SafePay Ransomware Group

SafePay distinguishes itself in the cybercrime landscape by employing a double-extortion strategy, encrypting files and threatening to release stolen data if ransom demands are unmet. The group uses LockBit source code and typically gains access to networks through valid credentials, often acquired via VPN gateways. This stealthy approach allows them to infiltrate systems without creating new user accounts, making detection more challenging.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.