Ransomware Group Targets IT Workers by Impersonating Legitimate Scanning Tool
The Hunters International threat group is targeting IT workers by impersonating a legitimate IP and port scanning tool to deliver malware to gain initial access to networks. Hunters International is a ransomware group that first emerged in October 2023. The group has been linked with the Hive ransomware group, which was the subject of a law enforcement operation and shut down in January 2023. While security researchers have suggested Hunters International was a rebrand of Hive due to a 60% code overlap with Hive, the group claims to have purchased the Hive code and that it is an independent group. Hunter’s International is not the most prolific ransomware group but has conducted more than 130 attacks so far this year. As the group’s name suggests, attacks are conducted worldwide, with the threat actor claiming victims in around 30 countries. The group primarily hunts for data, which is exfiltrated from victims’ networks. Threats are issued to publish the stolen data if a ransom is not paid, with the attacks often including file encryption. Hunters International poses a significant...
What is an NPI in Healthcare?
An NPI in healthcare is a ten-digit numeric National Provider Identifier issued by the Centers for Medicare and Medicaid Services (CMS) that must be used by HIPAA covered healthcare providers in all Part 162 transactions. In certain circumstances, an NPI in healthcare can also be issued to healthcare providers who are not covered by HIPAA. Prior to the passage of HIPAA, healthcare providers used a variety of codes to identify themselves in healthcare transactions (eligibility checks, authorization requests, claims and billing, etc.). The codes could be in different formats and of differing lengths depending on the type(s) of healthcare services being provided, industry standards, and/or the requirements of the paying entity. In 1993, the Health Care Financing Administration (now the CMS) undertook the task of replacing the COBRA-mandated Unique Physician Identification Number (UPIN) with a new identification system for all healthcare providers participating in the Medicare and Medicaid programs. The outcome was an eight-digit alphanumeric identifier that distinguished between...
Franklin County, Kansas Falls Victim to Ransomware Attack
Franklin County, Kansas recently fell victim to a ransomware attack that involved the theft of protected health information stored on its network. The attack was detected on May 20, 2024, and a nationally recognized digital forensics firm was engaged to assist with securing its network and investigating the incident. The investigation confirmed that on May 19, 2024, data had been exfiltrated, including the protected health information of individuals who had previously received services from the County Health Department and the County Adult Detention Center. The investigation and document review are ongoing, so it is currently unclear how many individuals have been affected. The breach has been reported to the HHS’ Office for Civil Rights as affecting at least 501 individuals. The total will be updated when the investigation and document review have been finished. Franklin County officials have confirmed that the compromised data includes names, addresses, Social Security numbers, dates of birth, diagnosis information, treatment information, medical record numbers, vaccination...
Rhysida Threat Group Auctions Data Stolen in City of Columbus Ransomware Attack
The City of Columbus in Franklin County, Ohio, recently fell victim to a ransomware attack that involved the theft of information stored on its network. The attack was detected on July 18, 2024, and the foreign threat actor attempted to deploy ransomware to encrypt files and solicit a ransom payment. The fast action of the Department of Technology limited exposure, which included severing the internet connection to prevent further unauthorized access, and the actions of the Department of Technology were successful in disrupting the threat actor’s activity. The threat actor was identified and information about the attack was shared with the Federal Bureau of Investigation (FBI) and the Department of Homeland Security. The city is working with those agencies and cybersecurity experts and is implementing additional safeguards to harden security to prevent similar attacks in the future. The investigation into the incident is ongoing, the city is in the process of issuing notifications to the affected individuals. Initially, it was thought that access was gained after an employee...
Arisa Health Confirms Data Breach Affected More Than 375,000 Patients
Arisa Health Incorporated in Arkansas has experienced a breach of the protected health information of 375,436 individuals. Cyberattacks and data breaches have also been reported by Sun City Pediatrics in Texas and Calibrated Healthcare in California. Arisa Health Incorporated Arisa Health Incorporated, an Arkansas-based integrated behavioral health system, has started notifying hundreds of thousands of patients about a recent cyberattack. The attack was detected on or around March 18, 2024, when connectivity to its network was disrupted. The forensic investigation confirmed that unauthorized individuals had access to its network between March 1, 2024, and March 18, 2024, and there may have been unauthorized access to files containing sensitive patient data. Those files may also have been exfiltrated from the network in the attack. The review of those files confirmed that the following data had been exposed: full names, addresses, email addresses, dates of birth, Social Security numbers, medical record numbers, health insurance numbers/Member IDs, certification of substance abuse...



