Fred Hutchinson Cancer Center ransomware attack led to extortion of patients
- Organization
- Fred Hutchinson Cancer Center
- Exploit
- Ransomware
- Industry
- Healthcare
Fred Hutchinson Cancer Center, a nonprofit cancer research and treatment organization in Seattle, said it detected unauthorized activity on its clinical network on November 19, 2023. The center quarantined affected servers, took parts of the clinical network offline and brought in federal law enforcement and an outside forensic firm. Fred Hutch said its clinics stayed open and continued treating patients throughout.
On December 15, the ransomware group Hunters International added Fred Hutch to its extortion site and claimed to hold roughly 533 GB of stolen data, publishing sample documents as proof and threatening to sell the material to data brokers.
The case drew attention because the attackers went after patients directly. According to reporting by The Record and Security Affairs, individuals received emails stating their records were among those of more than 800,000 people taken in the breach, and offering to remove a person's file from the batch for $50. The emails said the stolen records included names, Social Security numbers, phone numbers, medical histories, lab results and insurance details.
Fred Hutch said it would notify affected individuals once its review was complete. Security Affairs reported that by mid-December the group had removed the center's listing from its leak site, without explaining why.
Updates
-
Fred Hutchinson Cancer Center and the University of Washington agreed to an $11.5 million settlement covering more than 2.1 million people whose information was compromised, far above the 800,000 the attackers claimed in their extortion emails.