U.S. Sanctions Russian Bulletproof Hosting Service for Supporting LockBit Ransomware Attacks
Last week, the United States, United Kingdom, and Australia announced further action in ongoing efforts to disrupt the LockBit ransomware-as-a-service operation, including jointly designating Zservers for its role in supporting LockBit ransomware attacks and sanctioning two Russian nationals. LockBit is one of the most deployed ransomware variants. The group that shares the name was targeted in an international law enforcement operation, Operation Cronos, involving law enforcement agencies in 10 countries. Announced in February 2024, the operation caused significant disruption to the group’s operations at all levels. Infrastructure was seized, including the data leak site and 34 servers in multiple countries, along with cryptocurrency accounts linked to the group. International arrest warrants were issued, and arrests were made. The group recovered but has been operating in a limited capacity ever since. Efforts to disrupt the group are continuing. Almost a year after Operation Cronos was announced, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC),...
Is Grammarly HIPAA Compliant?
Grammarly is HIPAA compliant and can be used with other compliant content creation tools to write, share, and send content that contains Protected Health Information – provided covered entities subscribe to a Business Enterprise plan with a minimum of 100 seats. Unfortunately, this is the only subscription option for which Grammarly will enter into a Business Associate Agreement. Grammarly is an AI typing assistant that can be used with most desktop and mobile apps, browsers, and websites to write, share, and send error-free content. Depending on the subscription, Grammarly can also be used to generate content, summarize content, apply a consistent style/tone to content, and check for plagiarism. Due to its capabilities, Grammarly can greatly reduce the time it takes to get writing tasks completed and increase productivity. Using Grammarly in Healthcare Environments In healthcare environments, Grammarly can be used to help write emails, reports, and other medical documents – ensuring that potentially complex communications can be understood by patients, colleagues, and other...
January 2025 Healthcare Data Breach Report
December was a relatively quiet month for healthcare data breaches but data breaches were reported at a higher-than-average level in January, with 66 large healthcare data breaches reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR). OCR requires all data breaches at HIPAA-regulated entities to be reported, although only publishes breach report data for breaches that affect 500 or more individuals, which hereafter are referred to as large healthcare data breaches. Over the past 12 months, an average of 61 healthcare data breaches have been reported each month, with January 8.2% up on that average, making it one of the worst months for data breaches in the past 12 months. It should be noted that a single incident at a business associate – HCF Management – was reported individually by each of the 24 affected entities. Had that incident been reported as a single breach, January’s figures would look substantially better. While there was a 32% month-over-month increase in data breaches, there was a 34% fall in the number of individuals...
What are PII Encryption Requirements?
PII encryption requirements exist when federal, state, or industry regulations mandate the use of encryption to protect the confidentiality of Personally Identifiable Information at rest and/or in transit. When no such regulations exist, it is still advisable to encrypt PII to ensure it is undecipherable in the event it is disclosed to or accessed by an unauthorized party. All 50 states, the District of Columbia, Guam, Puerto Rico and the Virgin Islands have laws that require private businesses to notify State Attorney Generals and individuals when unsecured PII is disclosed or accessed without authorization. However, it has been estimated that only half of businesses have data encryption strategies that identify how PII is received, stored, and transmitted, and how it is protected from unauthorized disclosure or access. This is despite many federal, state, and industry regulations having mandatory PII encryption requirements. Businesses that fail to comply with the PII encryption requirements and subsequently suffer a data breach can face significant costs and regulatory...
Warning Issued BlackLock Ransomware Operation After 1,425% Increase in Data Leaks
A new ransomware-as-a-service (RaaS) group has rapidly accelerated attacks and could well become the most dominant RaaS group in 2025. According to a recently published ReliaQuest Threat Spotlight on the group, BlackLock was first observed in March 2024, initially operating under the name El Dorado, before rebranding as BlackLock in late 2024. BlackLock has risen to become a major player in the RaaS ecosystem following a May 2024 recruitment drive to attract new affiliates. By the end of Q4, 2024, BlackLock was the 7th most prominent ransomware variant, rising to 5th in January 2025, after a 1,425% increase in posts on its data leak site A user on the ransomware-focused Russian-language forum RAMP with the moniker $$$ has been instrumental in building a positive reputation for the group, which now surpasses rival groups such as Lynx, Dragonforce, and RansomHub on RAMP. In January 2025, BlackLock ranked 3rd in terms of post count on RAMP. By comparison, BlackLock had 9X as many posts on RAMP as the current most prominent ransomware group, RansomHub. Ransomware groups often use RAMP...



