Special Features

Cybersecurity Month

Ransomware forces hospital to turn away ambulances

Only level-one trauma unit in 400 miles crippled


Ransomware scumbags have caused a vital hospital to turn away ambulances after infecting its computer systems with malware.

The University Medical Center in Lubbock, west Texas, has been forced to severely limit operations following the cyberattack. The non-profit hospital was hit on Friday by ransomware operators. Services are still being disrupted, although most emergency care facilities are operating at present.

"Out of an abundance of caution, we will continue to temporarily divert incoming emergency and non-emergency patients via ambulance to nearby health facilities until this issue is resolved," the US hospital said in a statement.

"We are making accommodations wherever possible to minimize any disruption to our patients and our critical services. Our investigation into this incident remains ongoing and will take time to complete."

UMC is a level-one trauma hospital - meaning it's capable of handling the most seriously ill patients and maintains a team of specialists around the clock. The center is the only such hospital in nearly 400 miles and any degradation to its service could be life threatening.

The hospital said it noticed unusual activity on one of its IT networks and disconnected it from the main computer system. It has called in an unspecified third party to help fix the situation. A hospital spokesperson declined to comment further.

Hopefully the center is working with the FBI, which not only can sometimes help recover ransomware-scrambled systems, but will even help beat down the criminals on price if the victim decides to pay up, as FBI director Christopher Wray explained earlier this month.

According to Sophos, while the total number of ransomware attacks is falling slowly overall, when it comes to healthcare, they are rising. In the past two years, two-thirds of healthcare facilities surveyed by the infosec shop suffered at least one ransomware infection and over half had paid criminals to regain control of their networks.

"While we’ve seen the rate of ransomware attacks reach a kind of 'homeostasis' or even declining across industries, attacks against healthcare organizations continue to intensify, both in number and scope," said Sophos field CTO John Shier.

"The highly sensitive nature of healthcare information and need for accessibility will always place a bullseye on the healthcare industry from cybercriminals. Unfortunately, cybercriminals have learned that few healthcare organizations are prepared to respond to these attacks, demonstrated by increasingly longer recovery times. These attacks can have immense ripple effects." ®

Send us news
19 Comments

Ransomware's ripple effect felt across ERs as patient care suffers

389 US healthcare orgs infected this year alone

Senator accuses sloppy domain registrars of aiding Russian disinfo campaigns

Also, Change Healthcare sets a record, cybercrime cop suspect indicted, a new Mallox decryptor, and more

Would banning ransomware insurance stop the scourge?

White House official makes case for ending extortion reimbursements

Ransomware gang Trinity joins pile of scumbags targeting healthcare

As if hospitals and clinics didn't have enough to worry about

Akira ransomware is encrypting victims again following pure extortion fling

Crooks revert to old ways for greater efficiency

Sophos to snatch Secureworks in $859M buyout: Why fight when you can just buy?

Private equity giant Thoma Bravo adds another trophy to its growing collection

Healthcare Services Group discloses 'cybersecurity incident' in SEC filing

Laundry and dining provider still investigating cause and scope

Microsoft says more ransomware stopped before reaching encryption

Volume of attacks still surging though, according to Digital Defense Report

US healthcare org admits up to 400,000 people's personal info was snatched

It waited till just before Columbus Day weekend to make mandated filing, but don't worry, we saw it

Tardigrade genes may hold secret to radiation treatments for humans

Microscopic 'water bears' can survive blasts that would kill humans

Volkswagen monitoring data dump threat from 8Base ransomware crew

The German car giant appears to be unconcerned

INC ransomware rebrands to Lynx – same code, new name, still up to no good

Researchers point to evidence that scumbags visited the strategy boutique