FBI: Irish HSE hackers targeted 16 US healthcare orgs
Of the 400 organisations worldwide that have been hit by Conti, over 290 are located in the US


The Conti ransomware gang attempted to breach over a dozen US healthcare and first responder organisations, according to the Federal Bureau of Investigations (FBI).
The agency sent out a Traffic Light Protocol (TLP) alert on Thursday to help security teams defend their organisation's networks against future Conti attacks.
It suggested that 16 US services were targeted, including law enforcement agencies, 911 dispatch services and municipalities, all within the last 12 months.
"These healthcare and first responder networks are among the more than 400 organisations worldwide victimised by Conti, over 290 of which are located in the US," the FBI Cyber Division said.
Conti is a type of ransomware as a service (RaaS) operation that is thought to be deployed by a Russian group known as Wizard Spider. It shares some of the same code as the notorious Ryuk strain and has recently been linked to attacks on Ireland's Health Service Executive (HSE) and its Department of Health (DoH).
The DoH was able to prevent the Conti attack from encrypting its network but the HSE was not so lucky and was forced to shut down all its IT systems to prevent it from spreading further.
The US government has previously warned of ransomware attacks on its healthcare industry after Ryuk was used to takedown systems for Universal Health Services in October 2020.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The consequences of successful ransomware deployment on hospitals were fully realised last year when a man died after his ambulance had to be rerouted due to a Berlin hospital having its systems compromised.
Germany is fearing more attacks too, with its cyber security agency sending out an alert over the weekend that warned of an increased risk of hackers targeting hospitals. The agency's chief, Arne Schoenbohm, told Zeit Online that remote working has led to "a greater danger at hospitals".
Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.
Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.
-
Hackers breached a 158 year old company by guessing an employee password – experts say it’s a ‘pertinent reminder’ of the devastating impact of cyber crime
News A Panorama documentary exposed hackers' techniques and talked to the teams trying to tackle them
-
The ransomware boom shows no signs of letting up – and these groups are causing the most chaos
News Thousands of ransomware cases have already been posted on the dark web this year
-
Everything we know about the Ingram Micro cyber attack so far
News A cyber attack on Ingram Micro severely disrupted operations and has been claimed by the SafePay ransomware group.
-
A prolific ransomware group says it’s shutting down and giving out free decryption keys to victims – but cyber experts warn it's not exactly a 'gesture of goodwill'
News The Hunters International ransomware group is rebranding and switching tactics
-
Swiss government data published following supply chain attack – here’s what we know about the culprits
News Radix, a non-profit organization in the health promotion sector, supplies a number of federal offices, whose data has apparently been accessed.
-
Ransomware victims are getting better at haggling with hackers
News While nearly half of companies paid a ransom to get their data back last year, victims are taking an increasingly hard line with hackers to strike fair deals.
-
LockBit data dump reveals a treasure trove of intel on the notorious hacker group
News An analysis of May's SQL database dump shows how much LockBit was really making
-
‘I take pleasure in thinking I can rid society of at least some of them’: A cyber vigilante is dumping information on notorious ransomware criminals – and security experts say police will be keeping close tabs
News An anonymous whistleblower has released large amounts of data allegedly linked to the ransomware gangs