In late April 2023, the ALPHV ransomware gang asserted responsibility for an attack on Transformative Healthcare, extracting a terabyte of data encompassing medical records and paramedic reports. The target of the assault was Fallon Ambulance Services, a subsidiary of Transformative Healthcare and the now-defunct Ambulance Service operating in the greater Boston area. The ransomware incident exposed sensitive information affecting nearly a million individuals, as disclosed in a breach notification submitted to the Maine Attorney General. Around 911,757 individuals across the United States, including 20,486 Maine residents, were impacted by the breach, which occurred on February 17, 2023, and was detected on April 21, 2023. The unauthorized party accessed a server housing patient data, which the company claimed was stored for compliance with legal obligations. Despite Fallon Ambulance Services ceasing operations in December 2022, suspicious activity within its data storage archive was identified in April 2023. A third-party cybersecurity investigation revealed that personal information and COVID-19 testing details may have been compromised. Exposed data included names, driver's license numbers, and non-driver identification card numbers. Maine residents were officially notified on December 27, 2023. The Maine Attorney General advised individuals who received ambulance services from Fallon Ambulance Service between February and December 2022 to remain vigilant against potential identity threats. The ALPHV ransomware gang, targeted by law enforcement, had previously victimized high-profile entities like MGM Resorts, Amazon's Ring, and Reddit. Transformative Healthcare, offering free identity theft protection services to those affected, underscores the vulnerability of the healthcare sector to cyber threats. The incident highlights the imperative need for robust cybersecurity measures in the digitalized healthcare landscape, where the deliberate targeting of hospitals and emergency services by hackers poses significant risks to patient privacy.
Security researchers have revealed a highly sophisticated Linux rootkit named Singularity, which can bypass Elastic Security’s endpoint detection and response (EDR) mechanisms. T...
The Symantec Threat Hunter Team has uncovered two major cyber intrusions targeting Ukrainian organizations, attributed to Russian-aligned threat actors. Active from late June to Au...
Attackers based in China are taking advantage of vulnerabilities in Cisco ASA, which is widely used by governments and big organizations around the world. According to Palo Alto Ne...