Ransomware Attack on California Healthcare Provider Impacts 3.3 Million

Date:

February 23, 2023

World map

Overview

Title

Ransomware Attack on California Healthcare Provider Impacts 3.3 Million

Victim

Regal Medical Group

Attacker

Unknown

Location

Temecula, USA

Temecula, California

Size of Attack

Unknown/TBD

First Reported

February 23, 2023

Last Updated

October 31, 2022

A ransomware attack against California healthcare provider Regal Medical Group potentially exposed the personally identifiable (PII) and protected health information (PHI) of more than 3.3 million patients.

The attack took place in December and affected the systems at the Regal Medical Group and affiliates Lakeside Medical Organization, Affiliated Doctors of Orange County and the Greater Covina Medical Group.

“Affected PII and PHI includes names, addresses, birth dates, phone numbers, Social Security numbers, diagnosis and treatment information, health plan member numbers, laboratory test results, prescription details, and radiology reports,” according to SecurityWeek.

Takeaway: Ransomware attacks are the biggest threat facing organizations today, and healthcare providers have been hit particularly hard. Criminal ransomware groups know that the impact of an attack against healthcare organizations doesn’t just disrupt everyday business, it directly affects the lives of their patients, which puts tremendous pressure on the targeted provider to pay up for swift recovery.

The threat from ransomware is very real, and the fact that nation-state sponsored or directed operators are getting more active in conducting ransomware attacks is concerning. Last year CISA's Shields Up advised organizations to remain vigilant with respect to an increased risk from ransomware and destructive data attacks as a result of the Russian invasion of Ukraine and likelihood that ransomware attacks against Western targets are likely to escalate. As well, a joint alert was just issued (PDF) from CISA, the FBI, NSA, HHS, and several South Korean law enforcement agencies to be wary of ransomware attacks coming from North Korea targeting healthcare providers.

Criminal elements have significantly advanced their ability to quietly infiltrate large portions of a target's network in order to demand a higher ransom payout and exfiltrate sensitive data to be used as additional leverage to get the victims to pay. This is a big-money game, and we continue to see healthcare and other critical infrastructure providers be a favorite target given they typically have the least amount of resources to dedicate to securing these sensitive systems.

Updates: (descending from most recent)

healthcare providers have been hit particularly hard. Criminal Ransomware attacks against healthcare organizations don’t just disrupt everyday business, they directly affect the lives of patients...

Oh no!

This attack's description was not found, while we work on the detailed account of this attack we invite you to browse through other recent Rasomware Attacks in the table below.

Attack reported by

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.

lockbit attacks SpaceX
Date
March 15, 2023
Ransomware group
lockbit
Location

Hawthorne, USA

California, USA

Industry
Manufacturing
Victim
SpaceX
lockbit attacks SpaceX
Date
March 15, 2023
Ransomware group
lockbit
Location

Hawthorne, USA

California, USA

Industry
Manufacturing
Victim
SpaceX
alphv attacks Ring
Date
March 14, 2023
Ransomware group
alphv
Location

Santa Monica, USA

CA, USA

Industry
Information & Technology
Victim
Ring
alphv attacks Ring
Date
March 14, 2023
Ransomware group
alphv
Location

Santa Monica, USA

CA, USA

Industry
Information & Technology
Victim
Ring
medusa attacks Minneapolis Public Schools
Date
March 9, 2023
Ransomware group
medusa
Location

Minneapolis, USA

Minnesota, USA

Industry
Education
Victim
Minneapolis Public Schools
medusa attacks Minneapolis Public Schools
Date
March 9, 2023
Ransomware group
medusa
Location

Minneapolis, USA

Minnesota, USA

Industry
Education
Victim
Minneapolis Public Schools
IceFire Ransomware Targeting Linux Distributions
Date
March 9, 2023
Ransomware group
icefire
Location

, USA

, USA

Industry
Information & Technology
Victim
Linux Systems
IceFire Ransomware Targeting Linux Distributions
Date
March 9, 2023
Ransomware group
icefire
Location

, USA

, USA

Industry
Information & Technology
Victim
Linux Systems
lockbit3 attacks Indigo.ca
Date
February 28, 2023
Ransomware group
lockbit3
Location

Toronto, Canada

, Canada

Industry
Arts, Entertainment & Recreation
Victim
Indigo.ca
lockbit3 attacks Indigo.ca
Date
February 28, 2023
Ransomware group
lockbit3
Location

Toronto, Canada

, Canada

Industry
Arts, Entertainment & Recreation
Victim
Indigo.ca
Ransomware Attack on California Healthcare Provider Impacts 3.3 Million
Date
February 23, 2023
Ransomware group
Unknown
Location

Temecula, USA

California, USA

Industry
Healthcare
Victim
Regal Medical Group
Ransomware Attack on California Healthcare Provider Impacts 3.3 Million
Date
February 23, 2023
Ransomware group
Unknown
Location

Temecula, USA

California, USA

Industry
Healthcare
Victim
Regal Medical Group
HHS Alerts on Cl0p Ransomware Following GoAnywhere MFT Exploits
Date
February 23, 2023
Ransomware group
clop
Location

Washington, D.C., USA

, USA

Industry
Healthcare
Victim
Department of Health and Human Services
HHS Alerts on Cl0p Ransomware Following GoAnywhere MFT Exploits
Date
February 23, 2023
Ransomware group
clop
Location

Washington, D.C., USA

, USA

Industry
Healthcare
Victim
Department of Health and Human Services
BlackCat/ALPHV Ransomware Gang Hits City of Lakewood
Date
February 22, 2023
Ransomware group
alphv
Location

Lakewood, USA

California, USA

Industry
Victim
City of Lakewood
BlackCat/ALPHV Ransomware Gang Hits City of Lakewood
Date
February 22, 2023
Ransomware group
alphv
Location

Lakewood, USA

California, USA

Industry
Victim
City of Lakewood
royal attacks Unisco
Date
February 20, 2023
Ransomware group
royal
Location

Buena Park, USA

California, USA

Industry
Transportation & Warehousing
Victim
Unisco
royal attacks Unisco
Date
February 20, 2023
Ransomware group
royal
Location

Buena Park, USA

California, USA

Industry
Transportation & Warehousing
Victim
Unisco
Production at Agriculture Giant Dole Disrupted by Ransomware Attack
Date
February 17, 2023
Ransomware group
Unknown
Location

Charlotte, USA

North Carolina, USA

Industry
Agriculture
Victim
Dole
Production at Agriculture Giant Dole Disrupted by Ransomware Attack
Date
February 17, 2023
Ransomware group
Unknown
Location

Charlotte, USA

North Carolina, USA

Industry
Agriculture
Victim
Dole