logo

ALPHV is singling out healthcare sector, say FBI and CISA

ID: 93c58580-f6b4-5b60-850e-373739f77db2

STIX ID: report--93c58580-f6b4-5b60-850e-373739f77db2

Feed Name: Malwarebytes Blog

Threat Score
80/100

Date Published: 2024-02-28

Date Updated: 2026-04-28

...
...

CISA, FBI and HHS warn that the ALPHV/BlackCat ransomware group and affiliates have increasingly targeted the healthcare sector since mid-December 2023 (about 70 leaked victims), using social engineering, credential theft, and remote-access tools (AnyDesk, MegaSync, Splashtop) to exfiltrate data and deploy ransomware that can encrypt Windows, Linux, and VMware; the advisory and report note other groups (e.g., Rhysida), highlight substantial operational impact to healthcare, and provide mitigation guidance such as patching, EDR/MDR, segmentation, offline backups, and ransomware rollback capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.