Ransomware Attack by INTERLOCK Hits Drug Rehab Center DATS

Incident Date: Oct 24, 2024

Attack Overview
VICTIM
Drug and Alcohol Treatment Service
INDUSTRY
Healthcare Services
LOCATION
USA
ATTACKER
Interlock
FIRST REPORTED
October 24, 2024

Ransomware Attack on Drug and Alcohol Treatment Service by INTERLOCK

The Drug and Alcohol Treatment Service, Inc. (DATS), a leading outpatient rehabilitation center in Scranton, Pennsylvania, has fallen victim to a ransomware attack by the newly identified group INTERLOCK. This incident highlights the vulnerabilities faced by healthcare organizations, particularly those dealing with sensitive data.

About Drug and Alcohol Treatment Service

DATS is a prominent non-profit organization dedicated to addressing substance abuse and addiction issues within Lackawanna County. The center offers comprehensive outpatient treatment, counseling, and therapeutic services tailored to the unique needs of individuals struggling with addiction. Known for its holistic approach, DATS integrates mental health support alongside substance abuse treatment, making it a standout in the healthcare sector. The organization employs a team of licensed professionals committed to high-quality care, although specific employee numbers are not publicly available.

Details of the Ransomware Attack

The INTERLOCK ransomware group claims to have exfiltrated 133 GB of sensitive data from DATS, including the SAGE accounting database and personal information of employees. This breach poses significant challenges for the center, which is now tasked with safeguarding its operations and protecting the privacy of its staff. The attackers have employed a double-extortion tactic, threatening to leak the stolen data if their demands are not met within a 96-hour deadline.

Profile of the INTERLOCK Ransomware Group

INTERLOCK is a newly surfaced ransomware group known for its double-extortion approach. After infiltrating a victim's network, the group encrypts key files and exfiltrates data, leaving a ransom note that warns against attempts to alter files or use recovery tools. The group distinguishes itself by imposing a strict deadline and threatening to share stolen data with competitors or regulatory bodies, amplifying the financial and reputational risks for the affected organization.

Potential Vulnerabilities and Penetration Methods

Healthcare organizations like DATS are particularly vulnerable to ransomware attacks due to the sensitive nature of the data they handle. The exact method of penetration used by INTERLOCK remains unclear, but common tactics include exploiting unpatched software vulnerabilities, phishing attacks, and weak network security protocols. The attack on DATS underscores the critical need for enhanced cybersecurity measures in the healthcare sector.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.