Tag

Blackcat

All articles tagged with #blackcat

cybersecurity1 year ago

Bootkitty: Unveiling the First UEFI Bootkit Threat to Linux Systems

Researchers have discovered "Bootkitty," the first UEFI bootkit targeting Linux systems, developed by a group named BlackCat. Although currently a proof-of-concept with no real-world attacks reported, Bootkitty disables kernel signature verification and preloads unknown binaries during system startup. It bypasses UEFI Secure Boot by hooking authentication protocols and patching GRUB boot loader functions. The bootkit also includes a kernel module with rootkit capabilities, but no link to the ALPHV/BlackCat ransomware group has been found. This development highlights the expanding threat landscape beyond Windows systems.

cybersecurity1 year ago

"Change Healthcare Ransomware Attack Exposes Medical Data of Millions"

UnitedHealth has disclosed that a ransomware attack on its subsidiary, Change Healthcare, exposed a significant amount of sensitive medical and personal data for potentially a third of Americans. The stolen data includes health insurance details, medical records, billing information, and personal identifiers like Social Security numbers. The attack, conducted by the BlackCat ransomware gang, led to major disruptions in the US healthcare system and resulted in UnitedHealth paying a ransom, reportedly $22 million. Affected individuals will receive data breach notifications and can access free credit monitoring services.

cybersecurity1 year ago

"Healthcare Industry Hit by $22 Million Ransomware Attack, Disrupting Provider Payments and Drug Access"

A post on a hacker forum claims that UnitedHealth Group paid $22 million to the "Blackcat" ransomware gang to recover access to encrypted data and systems. While neither UnitedHealth nor the hackers have commented on the alleged ransom payment, a cryptocurrency tracing firm partially corroborated the claim. Large companies victimized by ransomware often opt to pay hackers to regain control of their networks, especially in cases of significant disruption. The break-in at UnitedHealth's Change Healthcare unit has caused widespread disruption, with the American Medical Association requesting emergency funds to help physicians affected by the outage.

cybersecurity1 year ago

"Healthcare Industry Grapples with Wave of Ransomware Attacks"

Ransomware attacks on healthcare, particularly the recent attack on UnitedHealth Group's subsidiary Change Healthcare by the BlackCat ransomware operation, have caused significant disruptions in the US healthcare system, impacting patient care and access to prescription drugs. The attack has led to the theft of 6TB of data containing personal information, prompting warnings from the FBI, CISA, and HHS. Additionally, other ransomware operations such as Rhysida and LockBit continue to target healthcare, while new variants like Mallox and Xorist have emerged. The cybersecurity community is on high alert as ransomware gangs exploit vulnerabilities and launch attacks, posing a significant threat to critical infrastructure and organizations worldwide.

cybersecurity-healthcare1 year ago

"UnitedHealth Cyberattack Causes Billing Delays and Prescription Access Threats"

UnitedHealth has attributed a disruptive cyber attack affecting healthcare providers to the group Blackcat, causing a week-long outage of its Change Healthcare system and hindering transactions between providers and insurance companies. The breach, which could last for weeks, has prompted the company to set up a loan program for affected healthcare providers. Blackcat, known for previous hacks, has claimed responsibility and allegedly stolen millions of patient records, including sensitive medical and insurance data. The US government has issued a $15 million reward for information on the group, and UnitedHealth is working with cybersecurity firms to address the situation.

cybersecurity1 year ago

"Pharmacies Struggle Amid Ongoing Cyberattack Outage Blamed on Nation-State"

A ransomware attack, attributed to the BlackCat group, has caused widespread outages at U.S. hospitals and pharmacies by targeting Change Healthcare, a major healthcare tech giant handling prescription processing for over 67,000 pharmacies. The attack, which began on February 21, has disrupted prescription fulfillment and processing, prompting warnings from organizations like the American Hospital Association to disconnect from affected systems. The incident has also impacted Tricare, the U.S. military's health insurance provider, and is linked to previous cyberattacks on companies like Norton and Reddit.

cybersecurity2 years ago

"Reddit Hackers Demand Ransom and API Changes, John Oliver and Elon Musk Make Headlines"

Ransomware group BlackCat, responsible for the cyberattack on Reddit in February, is demanding a $4.5 million payment to prevent it from publishing 80GB of data that it claims to have stolen from the site. The group is also insisting that Reddit reverse the API price changes that have caused controversy recently. BlackCat emerged in November 2021 and by July 2022 had compromised more than 100 organizations.

cybersecurity2 years ago

Reddit faces data breach threat, alternative platforms emerge.

Hackers known as BlackCat are threatening to release 80GB of confidential data stolen from Reddit during a February breach unless the company pays a $4.5 million ransom and reverses its controversial API pricing changes. Reddit confirmed the cyber incident in February, but said it had "no evidence" that personal user data had been stolen. BlackCat has also been linked to a March attack on Western Digital and a threat to leak data allegedly stolen from Amazon-owned video surveillance company Ring. Reddit has not yet responded to BlackCat's demands.