Rhysida ransomware gang demanded $1.3 million from Easterseals Central Illinois
- Organization
- Easterseals Central Illinois
- Exploit
- Ransomware
- Industry
- Non-profit
Easterseals Central Illinois, a Peoria-based affiliate of the national nonprofit that serves people with disabilities, seniors and veterans, was hit by a cyberattack that the organization detected on April 1, 2024. The intrusion disrupted network functionality and access to certain systems.
Easterseals said it immediately disconnected all access to its network and brought in outside cybersecurity specialists to investigate. Breach notification filings later placed the number of affected people at 14,855, revised upward from an initial placeholder figure of 500.
Information involved in the attack included full names, addresses, dates of birth, Social Security numbers, driver's license numbers, passport details, and medical and health information. Easterseals offered affected individuals 12 months of identity protection services.
In October 2024 the Rhysida ransomware group added Easterseals to its extortion site and demanded 20 bitcoin, roughly $1.3 million at the time, with a deadline of October 30. The Record reported that Easterseals did not respond to requests for comment on the listing. Rhysida had previously claimed attacks on healthcare providers including Prospect Medical Holdings and Lurie Children's Hospital in Chicago.
The organization said it had since deployed endpoint security software, moved to cloud-based servers, hardened credentials and added multifactor authentication.