PrimaryPlus Hit by Qilin Ransomware Group in Major Attack

Incident Date: Dec 11, 2024

Attack Overview
VICTIM
Primary Plus
INDUSTRY
Healthcare Services
LOCATION
USA
ATTACKER
Qilin
FIRST REPORTED
December 11, 2024

Qilin Ransomware Group Targets PrimaryPlus: A Detailed Analysis

PrimaryPlus, a Federally Qualified Health Center (FQHC) serving Northeastern Kentucky and Southern Ohio, has fallen victim to a ransomware attack orchestrated by the Qilin group. Known for its comprehensive healthcare services, PrimaryPlus is a significant provider in its region, offering primary care, pharmacy services, and specialized programs. With a workforce of 201-500 employees, the organization is dedicated to delivering affordable and accessible healthcare.

Attack Overview

The Qilin ransomware group, also known as Agenda, has claimed responsibility for the attack on PrimaryPlus. The group is notorious for its double extortion tactics, which involve encrypting data and threatening to leak sensitive information unless a ransom is paid. In this instance, Qilin asserts that it has successfully exfiltrated data from PrimaryPlus, potentially compromising patient information and operational data.

PrimaryPlus: A Healthcare Leader

PrimaryPlus stands out in the healthcare sector due to its commitment to community health and technological integration. The organization was among the first to adopt electronic health records (EHR), enhancing data management and security. However, this reliance on technology also makes it a target for cybercriminals. The healthcare sector is particularly vulnerable to ransomware attacks due to the critical nature of its services and the sensitivity of patient data.

Qilin Ransomware Group: A Persistent Threat

Emerging in July 2022, the Qilin group operates as a Ransomware-as-a-Service (RaaS) platform, providing affiliates with sophisticated tools to execute attacks. The group distinguishes itself through its use of advanced encryption algorithms and cross-platform targeting capabilities, focusing on Windows, Linux, and VMware ESXi environments. Qilin's ability to customize attacks for specific targets makes it a formidable adversary.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.