RansomHub Targets Costello Eye Surgeons in Major Data Breach
RansomHub Ransomware Attack on Costello Eye Physicians & Surgeons
Costello Eye Physicians & Surgeons, PLLC, a leading ophthalmic care provider in Central New York, has recently been targeted by the notorious ransomware group RansomHub. This attack has raised significant concerns about data security and patient privacy within the healthcare sector.
About Costello Eye Physicians & Surgeons
Costello Eye Physicians & Surgeons is a comprehensive eye care facility known for its advanced ophthalmological services. The practice specializes in cataract surgery, glaucoma treatments, and refractive surgeries, utilizing cutting-edge technology to enhance patient outcomes. With multiple locations across Central New York, including New Hartford and Rome, the practice is a regional leader in eye care. Their commitment to innovation and patient-centered care distinguishes them in the healthcare industry.
Attack Overview
The ransomware attack orchestrated by RansomHub has resulted in the exfiltration of sensitive data, including personally identifiable information and protected health information. A sample of 50GB of this data has been leaked on the dark web, highlighting the severity of the breach. This incident underscores the vulnerabilities healthcare organizations face, particularly those handling large volumes of sensitive patient data.
RansomHub's Modus Operandi
RansomHub, a Ransomware-as-a-Service group, emerged in early 2024 and quickly established itself as a formidable threat in the cybercrime landscape. Known for its aggressive affiliate model, RansomHub employs double extortion tactics, encrypting data and exfiltrating sensitive information to pressure victims into paying ransoms. The group is affiliated with former Knight ransomware actors and operates through cybercrime forums like RAMP.
Potential Vulnerabilities
Costello Eye Physicians & Surgeons, like many healthcare providers, is vulnerable to ransomware attacks due to the critical nature of the data they handle. RansomHub likely exploited vulnerabilities in the organization's IT infrastructure, potentially through phishing campaigns or unpatched system vulnerabilities. The healthcare sector's reliance on digital records and the high value of patient data make it an attractive target for ransomware groups.
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!