Arietis Health Settles MOVEit Data Breach Lawsuit for $2.8 Million
A $2.8 million settlement has been agreed to resolve a class action lawsuit against Arietis Health over a 2023 hacking incident that involved the protected health information of 1,975,066 individuals. Arietis Health, a provider of billing services to NorthStar Anesthesia, was one of more than 2,300 organizations to be affected by the mass exploitation of zero day vulnerability in Progress Software’s MOVEit Transfer solution in late May 2023. Arietis Health used the file transfer solution to transfer large files containing patient information. The Clop threat group exploited the vulnerability, gained access to the Arietis Health MOVEit environment between May 28 and May 31, 2024, and copied data from that environment. The Arietis Health data breach involved patient data from at least 54 healthcare organizations linked to NorthStar Anesthesia, with the compromised data including patient names, dates of birth, driver’s license or other state identification card numbers, addresses, Social Security numbers, medical record numbers, patient account numbers, health insurance information,...
Cyberattack on Arizona Business Associates Affects 78,000 Individuals
Data breaches have been announced by Ottawa Family Physicians in Kansas, CPS Solutions in Ohio, Turning Point of Central California, The Phoenix Rehabilitation and Nursing Center in New York, and Primary Health-SMMPP & U.S. HEALTHWORKS-SMMPP in Arizona. Primary Health-SMMPP & U.S. HEALTHWORKS-SMMPP A data breach has recently been reported that has affected the HIPAA business associates Primary Health-SMMPP and U.S. HEALTHWORKS-SMMPP. Both business associates are based in Arizona and provide healthcare-related services, including the distribution of rapid COVID test kits to schools and organizations in Arizona and other states. On or around December 13, 2024, unusual activity was identified in a server operated by Primary Health-SMMPP. A third-party digital forensics company was engaged to investigate the unauthorized activity and confirmed that an unauthorized third party had breached its defenses and may have viewed or copied data stored on the server. The server was reviewed to identify the individuals affected and the types of data involved, and that process was...
China-Based Threat Group Targets Healthcare with Malicious DICOM Installers
Ransomware groups are targeting healthcare organizations for financial gain, infiltrating networks, stealing data, then using ransomware to encrypt files. Cyber threat actors are also infiltrating healthcare networks and stealing data in much quieter attacks, where compromised healthcare organizations are not extorted and hackers remain in their networks indefinitely. Researchers at the cybersecurity firm Forescout have identified a new China-based threat group that is engaged in these quiet attacks, with one campaign involving weaponized installers for DICOM viewers. The installers are used to deliver a remote access trojan to create a backdoor and gain control of victims’ computers. Silver Fox (aka Void Arachne, The Great Thief of the Valley) is a relatively new threat group first identified in June 2024. Initially, the group was focused on Chinese victims, deploying ValleyRAT malware via SEO poisoning, social media, and text message-based attacks, often under the guise of VPN software and AI applications. The group has been highly active since it emerged and its tactics have...
Study Explores the Effectiveness of Insider Risk Management Programs
In 2024, the healthcare industry was rocked by a ransomware attack on Change Healthcare that caused massive disruption to healthcare operations across the country and resulted in the theft of the protected health information of more than 190 million individuals. According to Kroll, healthcare was the most attacked industry, overtaking finance, accounting for 23% of all data breaches last year. While hacking was the most common breach cause in 2024, many cybersecurity incidents were due to malicious and negligent insiders, and these incidents can be costly to resolve. A recent study by the Ponemon Institute on behalf of DTEX Systems sought to identify how prevalent insider breaches are, the financial impact of these incidents, and how organizations are addressing insider risk. The survey revealed that organizations are increasingly adopting insider risk management programs, with the percentage of companies that have an insider risk management program increasing from 77% in 2023 to 81% in 2024. The amount of the IT security budget devoted to insider risk management is also...
Healthcare Was the Most Breached Industry in 2024
A recent report from the financial and risk advisory firm Kroll has confirmed that healthcare is now the primary target for cybercriminals, having overtaken finance for data breaches in 2024. In 2024, healthcare accounted for almost one-quarter (23%) of all data breaches, overtaking finance (22%), albeit by the smallest of margins. In 2023, finance topped the list with 26% of data breaches with healthcare in second place with 18% of data breaches. Over the past few years, finance and healthcare have been vying for the top spot for data breaches, and there is no reason to suggest any change in 2025; however, the Kroll Data Breach Outlook 2025 report provides interesting insights into attacks on other sectors. Cyber actors are conducting fewer attacks on other often targeted sectors such as professional services, retail, technology, and education, with attacks on the technology sector falling by 46%, attacks on education falling by 38%, and retail attacks falling by 33%. Last year saw an increase in attacks on the industrial services, manufacturing, government, and insurance sectors,...



