BeneCare Dental Insurance Under Siege: Inside the Hunters Ransomware Assault

Incident Date:

April 3, 2024

World map

Overview

Title

BeneCare Dental Insurance Under Siege: Inside the Hunters Ransomware Assault

Victim

BeneCare Dental Insurance

Attacker

Hunters International

Location

Bala Cynwyd, USA

Pennsylvania, USA

First Reported

April 3, 2024

BeneCare Dental Insurance Targeted by Hunters Ransomware Group

Overview

BeneCare Dental Insurance, a company operating in the Healthcare Services sector since 1979, has been targeted by the Hunters ransomware group.

Company Profile

The company has a unique partnership model between dental professionals and a specialty administrator to underwrite group dental plans. BeneCare Dental Insurance is known for its group dental plans, offering lower administrative overhead, stable rates year-over-year, and more dollars allocated to patient care. While the exact size of the company is not explicitly stated, BeneCare is recognized as the largest dental insurer in the country for government-sponsored plans covering children and seniors.

Previous Attacks

The vulnerabilities that made BeneCare a target for the Hunters ransomware group are not specified. However, the LockBit ransomware group, known for its attacks, was responsible for a similar attack on Managed Care of North America (MCNA) in 2023. The LockBit group has targeted well-known companies like SpaceX and was linked to a Russian-Canadian citizen arrested in Ontario, Canada.

FBI Recommendations

The FBI advises against paying ransom in response to a ransomware attack. Paying ransom encourages perpetrators to target more victims and incentivizes others to get involved. Instead, the FBI recommends securing lost data and future security by addressing root causes of ransomware attacks, such as social engineering tactics like phishing, unpatched software, poor authentication, and the lack of multi-factor authentication.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.