Ransomware Attack Hits Legacy Treatment Services in New Jersey

Incident Date: Oct 26, 2024

Attack Overview
VICTIM
Legacy Treatment Services
INDUSTRY
Healthcare Services
LOCATION
USA
ATTACKER
Interlock
FIRST REPORTED
October 26, 2024

Ransomware Attack on Legacy Treatment Services by INTERLOCK Group

Legacy Treatment Services, a prominent nonprofit organization in New Jersey, has recently fallen victim to a ransomware attack orchestrated by the INTERLOCK group. This incident has raised significant concerns about the security of sensitive patient data and the operational impact on the organization.

About Legacy Treatment Services

Legacy Treatment Services is a comprehensive mental and behavioral health organization with a history spanning over 150 years. Based in Hainesport, New Jersey, the organization provides a wide array of services, including outpatient therapy, crisis intervention, and housing assistance for individuals with mental health challenges. With a mission to transform lives from "surviving to thriving," Legacy employs a multidisciplinary approach, emphasizing trauma-informed care and evidence-based practices. The organization operates across ten counties in New Jersey, employing a significant number of staff to support its extensive service offerings.

Details of the Ransomware Attack

The INTERLOCK ransomware group has claimed responsibility for the attack on Legacy Treatment Services, alleging the exfiltration of approximately 170 GB of sensitive data. This data reportedly includes internal documents, patient records, and a substantial SQL database. The attack highlights vulnerabilities in the organization's cybersecurity infrastructure, particularly concerning the protection of sensitive patient information. The attackers have imposed a 96-hour deadline for ransom payment, threatening to leak the stolen data if their demands are not met.

Profile of the INTERLOCK Ransomware Group

INTERLOCK is a newly identified ransomware group known for its double-extortion tactics. After infiltrating a victim's network, the group encrypts key files and exfiltrates data, leaving a ransom note that warns against attempts to alter files or use recovery tools. The group distinguishes itself by imposing strict deadlines and threatening to share stolen data with competitors or regulatory bodies, amplifying the financial and reputational risks for affected organizations. The exact method of infiltration in the Legacy Treatment Services attack remains unclear, but it underscores the need for enhanced cybersecurity measures in the healthcare sector.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.