TechCrunch reports that Barts Health NHS Trust, which is the largest trust of the UK's National Health Service, disclosed that an investigation regarding an ALPHV/BlackCat ransomware attack that led to the theft of 70TB of data, which the ransomware claims to be the largest health data breach in the UK, is underway.
ALPHV/BlackCat has already leaked some of the data allegedly exfiltrated from Barts Health, including employee identification files and confidential internal emails, the legitimacy of which has not been disputed by the NHS trust.
The data breach comes weeks after an NHS dataset with data from 1.1 million patients in 200 hospitals has been stolen in a ransomware attack against the University of Manchester.
Numerous cyberattacks have also been reported by the UK's public sector in recent months, with communications regulator Ofcom confirming compromise from the widespread Cl0p ransomware attack exploiting a vulnerability in the MOVEit Transfer file transfer app and a Black Basta ransomware attack impacting major UK outsourcing company Capita in May, resulting in the compromise of over 90 organizations.
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Aside from primarily leveraging basic usernames for their accounts, organizations impacted by ransomware intrusions from July to September — including those in the government and healthcare industries — also mostly failed to implement multi-factor authentication that could have deterred brute-force attacks.
Included in the Phobos-hit organizations that paid a ransom were a California public school system, a North Carolina children's hospital, a Maryland-based accounting and consulting service provider, and health organizations in Pennsylvania and Maryland, revealed an unsealed indictment against suspected Phobos administrator Evgenii Ptitsyn.
Alleged Scattered Spider hackers Ahmed Hossam Eldin Elbadawy, Noah Michael Urban, Evans Onyeaka Osiebo, Joel Martin Evans, and Tyler Robert Buchanan have been indicted for their involvement in a prolonged cryptocurrency theft operation that involved SMS phishing, corporate system compromise, and further phishing intrusions.