The Cybersecurity and Infrastructure Security Agency, FBI, Multi-State Information Sharing and Analysis Center (MS-ISAC) and international partners June 14 recommended health care and other critical infrastructure organizations take certain actions to defend their networks against LockBit ransomware based on observed incidents.

“The LockBit ransomware-as-a-service is one of the most prolific and aggressive ransomware strains targeting hospitals and health systems,” said John Riggi, AHA’s national advisor for cybersecurity and risk. “This group needs to understand that their attacks are not just ‘data’ crimes. They are, in fact, threat-to-life crimes. The impact of these attacks continues to disrupt patient care and risk patient safety at victim hospitals, often resulting in a regional disruption to care. As a field, we will continue to fully cooperate with the FBI, CISA and other agencies to help them identify and impose consequences on these perpetrators.”     

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org. For the latest cyber and risk resources and threat intelligence, visit AHA.org/cybersecurity.

Related News Articles

Headline
The Cybersecurity and Infrastructure Security Agency along with international agencies May 14 released guidance for high-risk nonprofit and other resource-…
Headline
Hospitals and health systems nationwide saw a sizable increase in delayed or missing payments in first quarter 2024, according to a report released May 10 by…
Headline
The Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of Health and Human Services, and Multi-State Information…
Headline
The Department of Justice May 7 announced more than two dozen criminal charges against Dimitry Yuryevich Khoroshev, 31, of Voronezh, Russia, for his alleged…
Headline
The AHA and other national hospital groups May 8 sent a letter to UnitedHealth Group, urging the organization to formally accept responsibility for issuing…
Headline
The Cybersecurity and Infrastructure Security Agency May 3 extended the comment period to July 3 for the April 4 proposed rule that would implement cyber…