Ransomware actors hijack hospital Facebook page, claim 6TB data theft
Attackers seized a health system's social media account during active incident response, claiming exfiltration of sexual assault records and mental health files.
A ransomware group has commandeered a hospital system's Facebook page while the organization continues responding to an ongoing cyberattack. The actors claim to have stolen 6 terabytes of data containing highly sensitive patient information.
The hijacked social media account represents an escalation in extortion tactics. The attackers say the exfiltrated data includes records related to sexual assault examinations, mental health treatment, abortion care, and sexual harassment incidents — categories that carry exceptional privacy risk and potential for individual harm beyond typical medical records.
The Facebook takeover occurred amid the hospital system's active incident response, suggesting the attackers retained sufficient access to enterprise credentials or exploited lingering vulnerabilities. Using a victim's own communication channels to amplify pressure is increasingly common among ransomware operators seeking to force payment or punish non-compliance.
- 01Hospital patients whose sensitive health records were accessed face identity theft and personal safety risks
- 02Health system faces regulatory scrutiny under HIPAA and potential class action litigation
- 03Healthcare CISOs must harden social media account security alongside clinical network defenses
- 04Insurers may face claims related to both data breach notification costs and individual harm
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.