RansomHub Ransomware Breach Exposes 1doc Patient Data

Incident Date: Oct 22, 2024

Attack Overview
VICTIM
1doc
INDUSTRY
Hospitals & Physicians Clinics
LOCATION
Singapore
ATTACKER
Ransomhub
FIRST REPORTED
October 22, 2024

RansomHub Ransomware Attack on 1doc: A Detailed Analysis

In a recent cyberattack, the ransomware group RansomHub has claimed responsibility for breaching 1doc, a prominent healthcare provider based in Singapore. This attack has resulted in the exfiltration of approximately 175 GB of sensitive data, including patient records, raising significant concerns about privacy and data protection.

About 1doc

1doc is an integrated healthcare platform developed by iAPPS Health Group, a Fin-MedTech company. Operating under the registered name 1DOC Medical Centre (Changi) Pte. Ltd., the company has been active since 2021. 1doc is known for its commitment to personalized healthcare, leveraging technology to offer innovative solutions such as the 1doc Health Kiosk and AI Health Assistant. The company collaborates with over 500 organizations, indicating a substantial operational scale within the healthcare sector. Their focus on 3P Medicine—personalization, prediction, and prevention—sets them apart in the industry.

Attack Overview

The attack on 1doc highlights the vulnerabilities faced by organizations handling sensitive information. RansomHub's breach of 1doc's defenses underscores the growing threat of ransomware attacks on the healthcare sector. The attackers have reportedly exfiltrated a significant amount of data, including patient records, which could have severe implications for patient privacy and trust.

RansomHub's Modus Operandi

RansomHub, a Ransomware-as-a-Service (RaaS) group, emerged in February 2024 and quickly established itself as a formidable player in the ransomware landscape. The group is known for its aggressive affiliate model and double extortion tactics, encrypting data and exfiltrating sensitive information to increase leverage in ransom demands. RansomHub's ransomware is optimized for speed and efficiency, targeting cross-platform systems and exploiting vulnerabilities in unpatched systems.

Potential Penetration Methods

RansomHub affiliates likely used a combination of phishing campaigns, vulnerability exploitation, and password spraying to gain initial access to 1doc's systems. The group's expertise in exploiting zero-day vulnerabilities and conducting multi-phase attacks involving network reconnaissance and privilege escalation could have facilitated the breach. The healthcare sector's reliance on critical data and the potential for operational disruption make it a prime target for such sophisticated ransomware groups.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.