U.Ok. healthcare large HCRG Care Group has confirmed it’s investigating a cybersecurity incident after a ransomware gang claimed to have breached the corporate’s methods to steal troves of delicate information.
HCRG Care Group is among the largest unbiased suppliers of group well being and care providers in the UK. The group, beforehand often called Virgin Care and now owned by Twenty20 Capita, companions with Nationwide Well being Service trusts and native authorities across the U.Ok. to ship healthcare providers, together with pressing care, sexual well being, and grownup and little one social care providers.
HCRG was this week listed on the darkish net leak website of the prolific Medusa ransomware group, which claims to have compromised the corporate to steal greater than two terabytes of knowledge.
Samples of the allegedly stolen information shared by Medusa and seen by TechCrunch seem to incorporate staff’ private info, delicate medical information, monetary information, and authorities identification paperwork, resembling passports and delivery certificates.
HCRG spokesperson Alison Klabacher informed TechCrunch in an emailed assertion that the corporate is “at the moment investigating an IT safety incident” and has “lately recognized a put up on the darkish net by a bunch claiming accountability.”
The corporate declined to say what forms of information have been accessed however didn’t dispute Medusa’s claims. HCRG additionally declined to say what number of people are affected. In response to the corporate’s web site, HCRG has greater than 5,000 staff and delivers healthcare providers to half one million sufferers throughout the UK.
“Our crew has not noticed any suspicious exercise because the implementation of rapid containment measures, and we’re working with exterior forensic specialists to research the incident, the spokesperson stated.
HCRG stated it knowledgeable the U.Ok.’s Info Commissioner’s Workplace and different regulators concerning the breach.
“Our providers are persevering with to function and safely see sufferers, and people with appointments or who must entry our providers ought to proceed to take action,” the corporate stated.
The Medusa ransomware group is threatening to publish the allegedly stolen information until HCRG pays the gang a ransom demand of $2 million.
HCRG wouldn’t verify the way it was compromised, however Medusa is thought to use unpatched vulnerabilities in remote desktop software.