Watsonville Hospital Faces Ransomware Threat from Termite Group

Incident Date: Dec 11, 2024

Attack Overview
VICTIM
Watsonville Community Hospital
INDUSTRY
Healthcare Services
LOCATION
USA
ATTACKER
Termite
FIRST REPORTED
December 11, 2024

Ransomware Attack on Watsonville Community Hospital by Termite Group

Watsonville Community Hospital (WCH), a critical healthcare provider in Watsonville, California, has fallen victim to a ransomware attack orchestrated by the Termite group. This incident underscores the vulnerabilities faced by healthcare institutions in the digital age.

About Watsonville Community Hospital

Established in 1895, Watsonville Community Hospital is a 106-bed facility serving the Santa Cruz community. It offers a wide range of medical and surgical services, including specialized pediatric and mental health care. The hospital is a nonprofit entity under the Pajaro Valley Health Care District, employing over 650 staff members and collaborating with more than 300 physicians. Despite its community-focused mission, WCH has faced financial challenges, reporting a net loss in recent years.

Details of the Ransomware Attack

On November 29, 2024, WCH experienced a significant IT disruption attributed to the Termite ransomware group. The attack led to the shutdown of internet access, electronic health records, and prescription notifications, forcing the hospital to revert to manual record-keeping. Termite has listed WCH on its dark web leak site, claiming to have infiltrated the hospital's database and providing sample screenshots as evidence. The hospital has acknowledged the disruption but has not confirmed the extent of the data compromise or any ransom demands.

Profile of the Termite Ransomware Group

Termite is a relatively new player in the ransomware landscape, first identified in November 2024. Operating on a ransomware-as-a-service model, Termite targets various sectors globally, including healthcare. The group is known for its data broker ransomware tactics, which involve encrypting and exfiltrating sensitive data, followed by threats to leak the information if ransoms are not paid. Termite's operations are characterized by their use of dark web forums for communication and ransom negotiations, maintaining a high level of anonymity.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.