News: 1687456628

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Now BlackCat extortionists threaten to leak stolen plastic surgery pics

(2023/06/22)


Ransomware gang BlackCat claims it infected a plastic surgery center, stole "lots" of highly sensitive medical records, and has vowed to leak patients' photos if the clinic doesn't pay up.

The notorious extortion crew, aka AlphaV, on Wednesday added the Beverly Hills Plastic Surgery to its list of compromised organizations, and bragged about swiping people's personal information and healthcare records, "including a lot of pictures of patients that they woud [sic] not want out there."

The note continued: "Leak to follow if no contact made."

[1]

Beverly Hills Plastic Surgery did not immediately respond to The Register 's inquiries. We will update this story if and when we hear back from the California clinic.

[2]

[3]

The [4]ransomware-as-a-service group's affiliates have been especially active lately, threatening to leak stolen Reddit data from a February intrusion and also posting sensitive information belonging to [5]Australian federal agencies and banks after breaching law firm [6]HWL Ebsworth earlier this year.

While threatening to make public before-and-after photos of nose jobs — and presumably more NSFW surgical enhancement pictures — is especially repulsive, even for criminals, it's not as original as it seems.

[7]

As Emsisoft Threat Analyst Brett Callow, who posted a [8]screenshot of the miscreants' leak threat, [9]pointed out : "This is not the first time a ransomware operation has threatened to release photos of cosmetic surgery photos."

REvil did it back in 2020 after [10]breaching The Hospital Group , which claims to be the UK's top weight loss and cosmetic surgery group.

[11]Reddit confirms BlackCat gang pinched some data

[12]FBI: BlackCat ransomware scratched 60-plus orgs

[13]Cancer patient sues hospital after ransomware gang leaks her nude medical photos

[14]Data leak at major law firm sets Australia's government and elites scrambling

More recently, other extortionists have become more personal in their threats, especially as they [15]increasingly target hospitals and other healthcare organizations entrusted with protecting very sensitive and private information.

In February, BlackCat broke into an [16]American healthcare provider — Lehigh Valley Health Network (LVHN) — and stole images of patients undergoing radiation oncology treatment along with other health records belonging to more than 75,000 people before posting at least some of that data online.

A cancer patient whose nude medical photos and records were shared [17]sued LVHN for allowing the "preventable" and "seriously damaging" leak.

[18]

If the gang's latest claims turn out to be true, and BlackCat did steal patient photos and protected health info belonging to Beverly Hills Plastic Surgery's clients, we'd expect to see similar lawsuits in the near future. ®

Get our [19]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZJTEfxIqrvBbRSrG230fNwAAAAw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZJTEfxIqrvBbRSrG230fNwAAAAw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZJTEfxIqrvBbRSrG230fNwAAAAw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2023/05/17/ransomware_affiliates_money/

[5] https://www.theregister.com/2023/06/20/hwl_ebsworth_cyber_incident/

[6] https://www.theregister.com/2023/06/20/hwl_ebsworth_cyber_incident/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZJTEfxIqrvBbRSrG230fNwAAAAw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://twitter.com/BrettCallow/status/1671515077969686529

[9] https://twitter.com/BrettCallow/status/1671515080591015938

[10] https://www.bbc.com/news/technology-55439190

[11] https://www.theregister.com/2023/06/20/reddit_confirms_blackcat_extortion_attempt/

[12] https://www.theregister.com/2022/04/25/in_brief_security/

[13] https://www.theregister.com/2023/03/15/cancer_lvhn_sues_hospital/

[14] https://www.theregister.com/2023/06/20/hwl_ebsworth_cyber_incident/

[15] https://www.theregister.com/2023/02/11/ransomware_regal_medical_group/

[16] https://www.theregister.com/2022/09/14/ransomware_medical_groups/

[17] https://www.theregister.com/2023/03/15/cancer_lvhn_sues_hospital/

[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZJTEfxIqrvBbRSrG230fNwAAAAw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[19] https://whitepapers.theregister.com/



Shamir’s Secret Sharing

Anonymous Coward

This isn’t rocket science, we mostly solved this risk a long time ago. There is no reason not to escrow parts of keys so that sensitive data which doesn’t need to be accessed constantly is always unintelligible to attackers by default.

Not to blame the actual victims (the patients) but the clinic deserves every bit of blame it gets here.

Re: Shamir’s Secret Sharing

Cybersaber

Nah, this is where security meets reality. SSS would not work in a medical setting because PEOPLE are a component of security, and doctors are (by and large) completely ignorant and intolerant of security and are key stakeholders in the business. Something as complicated to operate as Shamir's is not a good fit for this use case.

Re: Shamir’s Secret Sharing

b0llchit

But the stakeholders may also get sued by the patients for not keeping their data private. That may prove to be a lot more expensive in the end than improved procedural security.

Re: Shamir’s Secret Sharing

Cybersaber

Um, so yeah, it's not likely you've worked as IT in a medical practice. A doctor is too busy to sit down and understand or care about any of that. Does it help them with patients? Does it earn them more money? No?

That's what insurance is for. Go away and make my tablet work.

They're mostly not mean about it, they just don't have the mindset or inclination to understand mostly.

We've got the bits of your bits...

Cybersaber

Agreed, the focus should be on a proctology exam of the clinic's security. It's no charity hospital running on a shoestring budget. It's plastic surgery, they're not low-rent doctors.

Then if the clinic actually did an OK job on security, and the crooks got in through an insecure medical device or somesuch (a very, very real possibility) then regulators should go after the device manufacturers too.

God made the integers; all else is the work of Man.
-- Kronecker