Ransomware Hits Eye Clinic Surgicenter Exposing Data Risks

Incident Date: Oct 26, 2024

Attack Overview
VICTIM
The Eye Clinic Surgicenter
INDUSTRY
Hospitals & Physicians Clinics
LOCATION
USA
ATTACKER
Meow
FIRST REPORTED
October 26, 2024

Ransomware Attack on The Eye Clinic Surgicenter by Meow Group

The Eye Clinic Surgicenter, a prominent eye care facility in Billings, Montana, has become the latest victim of a ransomware attack by the notorious Meow Ransomware group. This attack underscores the vulnerabilities faced by healthcare providers, particularly those handling sensitive patient data.

About The Eye Clinic Surgicenter

Established in 1980, The Eye Clinic Surgicenter is a Medicare Certified Ambulatory Surgical Center specializing in comprehensive eye care and surgical services. The facility is equipped with two operating rooms and offers a wide range of ophthalmologic services, including advanced diagnostic and treatment options for conditions such as glaucoma, cataracts, and diabetic retinopathy. The clinic is known for its patient-centered approach and high patient satisfaction ratings, boasting a 4.9-star rating based on numerous reviews. Despite its reputation, the clinic's reliance on sensitive data makes it a prime target for cybercriminals.

Details of the Ransomware Attack

The Meow Ransomware group has claimed responsibility for the attack, demanding a ransom of $50,000 to prevent the release of over 59 GB of sensitive data. This data includes confidential employee and client information, such as Social Security numbers, medical records, and financial documents. The attackers are marketing this data to potential buyers, emphasizing its value to healthcare professionals and business analysts. The breach poses a significant threat to the clinic's operations and reputation, highlighting the critical need for effective cybersecurity measures in the healthcare sector.

Profile of Meow Ransomware Group

Meow Ransomware emerged in late 2022 and is associated with the Conti v2 ransomware variant. The group is known for targeting industries with sensitive data, particularly in the United States. They employ various infection methods, including phishing emails and exploiting Remote Desktop Protocol vulnerabilities. Meow Ransomware encrypts files using a combination of the ChaCha20 and RSA-4096 algorithms, leaving behind a ransom note instructing victims to contact them for negotiations. The group distinguishes itself by its aggressive tactics and the use of a data leak site to pressure victims into paying the ransom.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.