Cyber Crime

Memorial Health System forced to cancel surgeries after ransomware attack

Health organization Memorial Health System was hit by a disruptive cyber attack that forced it to cancel surgeries and divert patients last week.

The Memorial Health System announced that was hit by a disruptive cyber attack that forced it to suspend some of its operations. The organization operates the Marietta Memorial Hospital, the Selby General Hospital, and the Sistersville General Hospital, along with multiple provider clinics and outpatient service sites.

The attack disrupted clinical and financial operations, the organization suspended medical exams, cancelled surgeries, and patients have been diverted to other locations.

“Memorial Health System experienced an information technology security incident in the early morning hours this morning, August 15, 2021. As a result, we suspended user access to information technology applications related to our operations. We have implemented extensive information technology security protocols and is working diligently with security partners to restore information operations as quickly as possible.” reads the statement published by the company. “Federal law enforcement has also been notified.In the meantime, while this matter may result in temporary disruptions to certain aspects of our clinical and financial operations, we will continue to provide exceptional care to our community”

Memorial Health System president and CEO Scott Cantley said that the patient or employee data haven’t been publicly released or disclosed, he also added that the organization has been working with cybersecurity experts to mitigate the attack and recovery operations.

“We have reached a negotiated solution and are beginning the process that will restore operations as quickly and as safely as possible. We are following a deliberate, systematic approach to bring systems back online securely and in a manner that prioritizes our ability to provide patient care. This could happen as early as Sunday,” says Memorial Health System president and CEO Scott Cantley. “As we conduct our IT remediation work, our security experts have been monitoring and have not noted any indication that any patient or employee data has been publicly released or disclosed,” he said.

Cantley explained that its group is going to implement additional security improvements to prevent similar incidents.

The type of problems suffered by the organization suggests that it was hit by a ransomware attack, the statement of the CEO also refers to a negotiation to restore operations.

Researchers from Bleeping Computer speculate that the Memorial Health System was hit by Hive ransomware gang, a group that has been active since late June and that already targeted multiple victims.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Memorial Health System)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Experts warn of an ongoing malware campaign targeting WP-Automatic plugin

A critical vulnerability in the WordPress Automatic plugin is being exploited to inject backdoors and…

7 hours ago

Cryptocurrencies and cybercrime: A critical intermingling

As cryptocurrencies have grown in popularity, there has also been growing concern about cybercrime involvement…

9 hours ago

Kaiser Permanente data breach may have impacted 13.4 million patients

Healthcare service provider Kaiser Permanente disclosed a security breach that may impact 13.4 million individuals…

10 hours ago

Over 1,400 CrushFTP internet-facing servers vulnerable to CVE-2024-4040 bug

Over 1,400 CrushFTP internet-facing servers are vulnerable to attacks exploiting recently disclosed CVE-2024-4040 vulnerability. Over…

12 hours ago

Sweden’s liquor supply severely impacted by ransomware attack on logistics company

A ransomware attack on a Swedish logistics company Skanlog severely impacted the country's liquor supply. …

14 hours ago

CISA adds Cisco ASA and FTD and CrushFTP VFS flaws to its Known Exploited Vulnerabilities catalog

CISA adds Cisco ASA and FTD and CrushFTP VFS vulnerabilities to its Known Exploited Vulnerabilities…

1 day ago

This website uses cookies.