Value Dental Center Hit by Everest Ransomware Attack

Incident Date: Nov 13, 2024

Attack Overview
VICTIM
Value Dental Center
INDUSTRY
Hospitals & Physicians Clinics
LOCATION
USA
ATTACKER
Everest
FIRST REPORTED
November 13, 2024

Ransomware Attack on Value Dental Center by Everest Group

On November 13, Value Dental Center Cicero, a dental clinic in Illinois, became the latest victim of a ransomware attack by the notorious Everest group. This incident has compromised the personal and medical data of approximately 5,000 patients, raising significant concerns about patient privacy and the clinic's operational integrity.

About Value Dental Center

Value Dental Center operates in the Hospitals & Physicians Clinics sector, providing comprehensive dental services in Cicero, Illinois. The clinic is known for its patient-centered approach, offering a wide range of services from preventive to cosmetic dentistry. With a workforce of 51 to 200 employees, the center is a moderate-sized operation that emphasizes affordable, high-quality care. This focus on affordability and quality distinguishes it in the competitive dental market.

Vulnerabilities and Targeting

The healthcare sector, including dental practices like Value Dental Center, has become a prime target for ransomware groups due to the sensitive nature of the data they handle. The clinic's emphasis on accessibility and affordability may inadvertently expose it to cyber threats, as smaller healthcare providers often lack the cybersecurity infrastructure of larger organizations. This makes them attractive targets for groups like Everest, which exploit vulnerabilities to gain unauthorized access to sensitive information.

Attack Overview

The Everest ransomware group, known for its double extortion tactics, has claimed responsibility for the attack on Value Dental Center. The group has released screenshots of the extracted data as evidence, demanding the clinic make contact before a specified deadline to prevent further exposure. The exact size of the data leak remains unspecified, but the nature of the stolen data suggests significant implications for patient privacy.

About the Everest Ransomware Group

Everest is a Russian-speaking cybercriminal organization active since December 2020. It has gained notoriety for targeting the healthcare sector, employing sophisticated tactics such as lateral movement and credential access to infiltrate networks. The group distinguishes itself by not only encrypting data but also threatening to leak it, increasing pressure on victims to comply with ransom demands. Everest's focus on healthcare entities highlights the critical need for enhanced cybersecurity measures in this sector.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.