US hospitals forced offline by reported Ryuk ransomware attack
Universal Health Services employees have been told IT issues could go on for days
Universal Health Services (UHS), one of America's largest healthcare providers, has been hit by an alleged ransomware attack.
The company's IT networks have been taken offline by what is thought to be another case of Ryuk ransomware.
The most popular ransomware strains targeting UK businesses Selective ransomware Ryuk nets $4m from big businesses Spanish Ryuk ransomware attack hints at new WannaCry
Despite being relatively new, Ryuk has quickly built a fearsome reputation for attacks on enterprise-level businesses. It is ransomware that uses encryption to block access to a system until a ransom is paid.
This strain of malware hit UHS systems on Sunday, according to reports, shutting down its IT networks and forcing its workers to use "offline documentation". UHS provides healthcare for profit at some 400 hospitals and facilities across the US and in the UK.
"The IT network across Universal Health Services facilities is currently offline due to an IT security issue," the organisation said in a statement. "We implement extensive IT security protocols and are working diligently with our IT security partners to restore operations as quickly as possible."
One hospital worker told TechCrunch that their computer screen changed with text that referenced the "shadow universe", which is often the case with Ryuk ransomware attacks.
"Everyone was told to turn off all the computers and not to turn them on again," the unnamed person said. "We were told it will be days before the computers are up again."
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
It is not immediately known what effect the attack is having on patient care, or how widespread the infection is, but UHS has said that "no patient or employee data appears to have been accessed, copied or otherwise compromised".
Although the exact origin of Ryuk is unknown, it has been linked to a Russian cyber crime group called WizardSpider, which are known to go "big game hunting" - meaning they target larger organisations.
A number of Spanish organisations were hit by the ransomware earlier in the year, and there are fears it could lead to 'WannaCry' levels of disruption.
Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.
Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.
-
Manufacturers report millions in losses as downtime wreaks havoc on operationsNews UK manufacturers are losing up to £736 million every week due to downtime, according to new research, with outages lasting for several days on end.
-
Microsoft gives OpenAI restructuring plans the green lightNews The deal removes fundraising constraints and modifies Microsoft's rights to use OpenAI models and products
-
Volkswagen confirms security ‘incident’ amid ransomware breach claimsNews Volkswagen has confirmed a security "incident" has occurred, but insists no IT systems have been compromised.
-
The number of ransomware groups rockets as new, smaller players emergeNews The good news is that the number of victims remains steady
-
Teens arrested over nursery chain Kido hacknews The ransom attack caused widespread shock when the hackers published children's personal data
-
NCA confirms arrest after airport cyber disruptionNews Disruption is easing across Europe following the ransomware incident
-
Cyber professionals are losing sleep over late night attacksNews Hackers are biding their time and launching attacks when businesses can’t respond
-
Prolific ransomware operator added to Europe’s Most Wanted list as US dangles $10 million rewardNews The US Department of Justice is offering a reward of up to $10 million for information leading to the arrest of Volodymyr Viktorovych Tymoshchuk, an alleged ransomware criminal.
-
Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attackNews The attack on Jaguar Land Rover highlights the growing attractiveness of the automotive sector
-
Ransomware attack on IT supplier disrupts hundreds of Swedish municipalitiesNews The attack on IT systems supplier Miljödata has impacted public sector services across the country
