RansomHouse attacks Keralty

Incident Date:

November 27, 2022

World map

Overview

Title

RansomHouse attacks Keralty

Victim

Keralty

Attacker

Ransomhouse

Location

Bogota, Colombia

, Colombia

First Reported

November 27, 2022

RansomHouse Ransomware Gang Attacks Keralty

The RansomHouse ransomware gang has attacked Keralty. Keralty is a Colombian healthcare provider that operates an international network of 12 hospitals and 371 medical centers in Latin America, Spain, the US, and Asia. Keralty employs 24,000 people and 10,000 medical doctors who provide healthcare to over 6 million patients. The attack impacted Colombia’s healthcare systems, with patients reporting wait times of up to 12 hours in the wake of the attack.

Attack Details

Researchers first detected the attack on November 30th, 2022, when RansomHouse published Keralty to its data leak site, claiming to have stolen 3TB of data. It is unclear whether these claims hold any weight.

Keralty's Response

A translated statement from Keralty reads: "The computer servers of the Keralty Group companies have been the object of a cyberattack, which has generated technical failures in our systems. From the moment it was identified, we have been working 24 hours a day, both from the technological team and from the medical and administrative team, to provide continuity of care to our members. Likewise, from the beginning, this situation was brought to the attention of the competent authorities and the respective criminal investigation has been initiated. In order to maintain attention to our users, from Keralty We continue to implement the necessary contingency plans to maintain the service."

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.