Security News > 2021 > May > Scripps Health still grappling with impact of May 1 ransomware attack

A May 1 ransomware attack against California hospital chain Scripps Health continues to impact both the organization and its patients almost a month later.
On Monday, Scripps Health published an FAQ with new details about the attack as well as directions for affected patients.
Beyond the potential impact on patient data, questions remain as to who is behind the attack and why they targeted Scripps.
"It's realistically possible that this was more of a target-of-opportunity for a ransomware attack or didn't involve groups that talk about it publicly. Without knowing the details about attack indicators or how Scripps' infrastructure was protected, it would be hard to say how or why they were specifically attacked."
"There is strong correlation between the Ireland's health system attack and the Scripps attack because of the type of ransomware that was executed-Conti," said Matt Klein, cyber executive adviser at Coalfire.
"The Conti ransomware operation first appeared in May 2020 and is believed to be under the control of the Russia-based Wizard Spider cybercrime gang. Scripps was most likely targeted because of the level of revenue generated by their health system, which would lead an attacker to believe the chance for payment would be much greater."
News URL
Related news
- Medusa ransomware group claims attack on UK's Gateshead Council (source)
- Ransomware attack forces Brit high school to shut doors (source)
- Ransomware gangs pose as IT support in Microsoft Teams phishing attacks (source)
- Security pros more confident about fending off ransomware, despite being battered by attacks (source)
- Only 13% of organizations fully recover data after a ransomware attack (source)
- Ransomware attack at New York blood services provider – donors turned away during shortage crisis (source)
- Ransomware attack disrupts New York blood donation giant (source)
- Indian tech giant Tata Technologies hit by ransomware attack (source)
- US indicts 8Base ransomware operators for Phobos encryption attacks (source)
- RA World Ransomware Attack in South Asia Links to Chinese Espionage Toolset (source)