Friday, 21 February 2025
27.8 C
Singapore
32.3 C
Thailand
21.7 C
Indonesia
25.9 C
Philippines

UK healthcare provider HCRG confirms cyberattack after ransomware gang claims data theft

UK healthcare provider HCRG Care Group confirms a cyberattack after the Medusa ransomware gang claims to have stolen sensitive employee and patient data.

HCRG Care Group, one of the UKโ€™s largest independent healthcare providers, has confirmed investigating a cybersecurity breach after a notorious ransomware group claimed to have stolen a large amount of sensitive data.

The healthcare organisation, formerly Virgin Care and now owned by Twenty20 Capita, provides various community health and social care services across the UK. It partners with NHS trusts and local authorities to deliver essential services, including urgent care, sexual health clinics, and adult and child social care support.

This week, HCRG was listed on the Medusa ransomware gang’s dark web leak site. The group claims to have infiltrated the companyโ€™s systems and stolen over two terabytes of data. If true, this could pose a serious risk to employees and patients.

Sensitive data potentially compromised

According to samples of the alleged stolen files shared by Medusa, the data may include employeesโ€™ personal details, sensitive medical records, financial information, and government-issued documents such as passports and birth certificates.

Alison Klabacher, a spokesperson for HCRG, confirmed in an email statement that the company is โ€œcurrently investigating an IT security incidentโ€ and has โ€œrecently identified a post on the dark web by a group claiming responsibility.โ€

While HCRG has not confirmed the data type affected, Medusaโ€™s claims have not been denied. The organisation has also not disclosed how many individuals may be impacted. HCRG employs over 5,000 staff and provides care to around half a million patients across the country, making the scale of the potential breach significant.

โ€œOur team has not observed any suspicious activity since the implementation of immediate containment measures, and we are working with external forensic specialists to investigate the incident,โ€ the spokesperson said. HCRG has also informed the UKโ€™s Information Commissionerโ€™s Office (ICO) and other regulators about the breach.

Despite the cyberattack, HCRG reassured the public that its services remain operational. โ€œOur services are continuing to operate and safely see patients, and those with appointments or who need to access our services should continue to do so,โ€ the company added.

Ransom demand and ongoing risks

The Medusa ransomware gang is demanding a US$2 million ransom to prevent the publication of the allegedly stolen data. HCRG has not confirmed whether it will negotiate with the hackers or pay the ransom.

It is still unclear how Medusa breached HCRGโ€™s systems, but the group is known for exploiting unpatched vulnerabilities in remote desktop software. Cybersecurity experts warn that organisations handling sensitive information must remain vigilant against these attacks, which are becoming increasingly common in the healthcare sector.

As investigations continue, affected individuals may face identity theft and fraud risks. Patients and employees are urged to stay alert for any signs of misuse of their personal information.

Hot this week

Duolingoโ€™s Cybertruck stunt โ€˜killsโ€™ mascot Duo, and users canโ€™t get enough

Duolingoโ€™s marketing stunt claims its mascot, Duo the Owl, was hit by a Cybertruckโ€”boosting app engagement and sparking a viral campaign.

SBF and MINDEF launch first nationwide business phishing exercise to strengthen cyber resilience

SBF and MINDEF launched Singaporeโ€™s first nationwide business phishing exercise to boost cyber resilience, involving 200 organisations and 7,000 employees.

Tesla refreshes Model Y for Singapore, adding new features and design updates

Teslaโ€™s refreshed Model Y is now available in Singapore with an updated design, improved interior features, and enhanced performance.

Murena launches โ€˜deGoogledโ€™ Pixel Tablet for privacy-conscious users

Murena launches a privacy-focused Pixel Tablet without Google apps, running /e/OS for a secure, deGoogled experience. It is now available for US$549.

YouTube TV strikes new deal to keep Paramount channels

YouTube TV and Paramount reached a deal to keep CBS, Nickelodeon, and other content on Googleโ€™s pay-TV service, avoiding content removal.

Google expands in-car apps, turning vehicles into mobile entertainment hubs

Google is expanding its in-car apps, bringing more streaming and gaming options to vehicles with built-in Google services, starting with Volvo and Polestar.

Singapore businesses embrace AI to boost efficiency

Singapore businesses and government agencies use AI to improve efficiency, reduce costs, and enhance productivity, as shared at Microsoftโ€™s AI Tour.

Sonar acquires AutoCodeRover to boost AI-powered software development

Sonar acquires AutoCodeRover to enhance AI-powered coding, automating debugging, improving security, and speeding up software development.

ASUS launches ZenScreen Duo OLED MQ149CD, a portable monitor with dual OLED displays

ASUS unveils the ZenScreen Duo OLED MQ149CD, a portable dual-screen monitor with OLED technology, delivering stunning visuals and flexible work setups.

Related Articles