US hospitals forced offline by reported Ryuk ransomware attack
Universal Health Services employees have been told IT issues could go on for days
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
Universal Health Services (UHS), one of America's largest healthcare providers, has been hit by an alleged ransomware attack.
The company's IT networks have been taken offline by what is thought to be another case of Ryuk ransomware.
The most popular ransomware strains targeting UK businesses Selective ransomware Ryuk nets $4m from big businesses Spanish Ryuk ransomware attack hints at new WannaCry
Despite being relatively new, Ryuk has quickly built a fearsome reputation for attacks on enterprise-level businesses. It is ransomware that uses encryption to block access to a system until a ransom is paid.
This strain of malware hit UHS systems on Sunday, according to reports, shutting down its IT networks and forcing its workers to use "offline documentation". UHS provides healthcare for profit at some 400 hospitals and facilities across the US and in the UK.
"The IT network across Universal Health Services facilities is currently offline due to an IT security issue," the organisation said in a statement. "We implement extensive IT security protocols and are working diligently with our IT security partners to restore operations as quickly as possible."
One hospital worker told TechCrunch that their computer screen changed with text that referenced the "shadow universe", which is often the case with Ryuk ransomware attacks.
"Everyone was told to turn off all the computers and not to turn them on again," the unnamed person said. "We were told it will be days before the computers are up again."
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
It is not immediately known what effect the attack is having on patient care, or how widespread the infection is, but UHS has said that "no patient or employee data appears to have been accessed, copied or otherwise compromised".
Although the exact origin of Ryuk is unknown, it has been linked to a Russian cyber crime group called WizardSpider, which are known to go "big game hunting" - meaning they target larger organisations.
A number of Spanish organisations were hit by the ransomware earlier in the year, and there are fears it could lead to 'WannaCry' levels of disruption.
Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.
Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.
-
ITPro Excellence Awards winners unveiledIt's time to celebrate excellence in IT. Read on for the full list of winners...
-
This new mobile compromise toolkit enables spyware, surveillance, and data theftNews The professional package allows even unsophisticated attackers to take full control of devices
-
Ransomware gangs are sharing virtual machines to wage cyber attacks on the cheap – but it could be their undoingNews Thousands of attacker servers all had the same autogenerated Windows hostnames, according to Sophos
-
Google issues warning over ShinyHunters-branded vishing campaignsNews Related groups are stealing data through voice phishing and fake credential harvesting websites
-
The FBI has seized the RAMP hacking forum, but will the takedown stick? History tells us otherwiseNews Billing itself as the “only place ransomware allowed", RAMP catered mainly for Russian-speaking cyber criminals
-
Everything we know so far about the Nike data breachNews Hackers behind the WorldLeaks ransomware group claim to have accessed sensitive corporate data
-
There’s a dangerous new ransomware variant on the block – and cyber experts warn it’s flying under the radarNews The new DeadLock ransomware family is taking off in the wild, researchers warn
-
Hacker offering US engineering firm data online after alleged breachNews Data relating to Tampa Electric Company, Duke Energy Florida, and American Electric Power was allegedly stolen
-
Cybersecurity experts face 20 years in prison following ransomware campaignTwo men used their tech expertise to carry out ALPHV BlackCat ransomware attacks
-
15-year-old revealed as key player in Scattered LAPSUS$ HuntersNews 'Rey' says he's trying to leave Scattered LAPSUS$ Hunters and is prepared to cooperate with law enforcement
