Ransomware attack on OneBlood disrupted blood supply across the Southeast

Organization
OneBlood
Exploit
Ransomware
Industry
Nonprofit Blood Services

OneBlood, a nonprofit blood centre supplying hospitals across Florida, Georgia, Alabama, North Carolina and South Carolina, disclosed on July 31, 2024 that it was responding to a ransomware attack that had disrupted its information systems.

The organisation said collection, testing and distribution continued but at significantly reduced capacity, because staff had reverted to manual procedures in place of the software that normally manages blood donations. The American Hospital Association reported that hospitals served by OneBlood were asked to activate their critical blood shortage protocols and to apply conservation and prioritisation measures. OneBlood issued an urgent appeal for O positive, O negative and platelet donations, and an AABB task force coordinated support from other blood centres. Accounts of the number of hospitals involved ranged from about 250 to more than 350.

OneBlood said at the time that its investigation into whether donor records had been affected was continuing, and that it would offer credit monitoring if exposure was confirmed. It later determined that intruders had access to its network between July 14 and July 29, 2024, and that files containing the names and Social Security numbers of 167,400 people had been taken. Notification letters went out from around January 9, 2025.

Output for the hospitals it serves was reported back to normal by August 8, 2024. OneBlood subsequently agreed to pay up to $1 million to settle a class action brought by donors.

Sources