HC3 TLP Clear Analyst Note KillNet's Targeting of the HPH Sector December 2022 March 2023

Executive Summary

Pro-Russia hacktivist group, KillNet, has actively targeted the United States health and public health (HPH) sector since December 2022. Their signature distributed denial-of-service (DDoS) attacks on critical infrastructure sectors typically only cause service outages lasting several hours or even days. However, the range of consequences from these attacks on the HPH sector can be significant, threatening routine to critical day-to-day operations. An examination of the group’s cyber offensive from December 2022 to March 2023 provides insight into how and why they target the healthcare industry, and recommendations for how HPH organizations can better protect themselves.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272