RansomHub claimed a cyberattack on Planned Parenthood of Montana
- Organization
- Planned Parenthood of Montana
- Exploit
- Ransomware
- Industry
- Healthcare
Planned Parenthood of Montana identified a cybersecurity incident on 28 August 2024 and took parts of its network offline as a precaution while it worked through its incident response plan. The affiliate confirmed the attack publicly in early September, after the RansomHub extortion group named it on a dark web leak site.
RansomHub posted the listing on 4 September, claimed to have taken 93 gigabytes of data and published screenshots of administrative, financial and legal documents as proof. It set a deadline of 11 September for payment before threatening to release the files. CyberScoop reported that the sample material published at that stage did not appear to contain private patient records.
Martha Fuller, the affiliate's president and chief executive, said the matter had been reported to federal law enforcement and that IT staff and outside cybersecurity partners were working around the clock to restore affected systems securely. CyberScoop noted that the intrusion came days after Montana certified signatures for a November ballot measure on abortion rights.
Later investigation placed the intrusion window at 24 to 28 August 2024 and established that the protected health information of 56,917 people had been taken. The exposed data included names, addresses, dates of birth, medical record numbers, health insurance information and clinical details such as provider names, dates of service, diagnoses, treatments and prescriptions. Notification letters were mailed on 5 November 2024.