Ransomware Attack on Gramercy Surgery Center by Everest Group Exposes 465GB of Data

Incident Date:

July 15, 2024

World map

Overview

Title

Ransomware Attack on Gramercy Surgery Center by Everest Group Exposes 465GB of Data

Victim

Gramercy Surgery Center

Attacker

Everest

Location

New York, USA

New York, USA

First Reported

July 15, 2024

Ransomware Attack on Gramercy Surgery Center by Everest Group

Overview of Gramercy Surgery Center

Gramercy Surgery Center, established in 2006, is a prominent outpatient surgical facility located in New York City, serving the communities of Manhattan and Queens. Recognized as one of the leading multispecialty centers in the area, it was rated a top outpatient surgery center by Newsweek in 2021. The center specializes in a wide array of outpatient surgical procedures, providing high-quality patient care through advanced medical technology and a skilled healthcare team.

Details of the Ransomware Attack

On July 16, 2024, Gramercy Surgery Center fell victim to a ransomware attack orchestrated by the Everest ransomware group. The attack resulted in a significant data breach, compromising 465GB of sensitive information. This incident highlights the growing threat of cyberattacks on healthcare institutions and underscores the critical need for robust cybersecurity measures to protect patient data and maintain operational integrity.

About the Everest Ransomware Group

The Everest Ransomware Group is a notorious cybercriminal organization active since at least December 2020. Known for its involvement in ransomware attacks, data exfiltration, and initial access brokering, Everest targets organizations across various industries, including healthcare. The group employs a combination of legitimate compromised user accounts and Remote Desktop Protocol (RDP) for lateral movement, using AES and DES algorithms to encrypt files.

Vulnerabilities and Penetration

Healthcare institutions like Gramercy Surgery Center are particularly vulnerable to ransomware attacks due to the sensitive nature of the data they handle and the critical need for operational continuity. The Everest group likely penetrated Gramercy's systems through compromised user accounts or vulnerabilities in their RDP setup. The attack underscores the importance of stringent cybersecurity measures, including regular system updates and employee training on recognizing phishing attempts.

Impact on Gramercy Surgery Center

Gramercy Surgery Center employs approximately 63 individuals and reports an annual revenue of about $13.2 million. The attack not only jeopardizes patient data but also threatens the center's reputation and operational efficiency. As a leading outpatient surgical facility, Gramercy must now navigate the challenges of restoring its systems and regaining patient trust.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.