Connect with us

Hi, what are you looking for?


Data Breaches

Ransomware Gang Claims Attack on Capital Health

The LockBit ransomware gang claims to have stolen over 7 terabytes of data from hospital system Capital Health.

The LockBit ransomware gang over the weekend claimed responsibility for a November 2023 cyberattack on hospital system Capital Health.

In December, Capital Health announced that it fell victim to a cyberattack that resulted in network outages, and that it immediately launched an investigation, informed law enforcement, and started the restoration process.

“At this time, all services are available at our facilities, all systems have been restored, and all operations have returned to normal,” the organization said in an incident notification.

Capital Health also noted that it was working with a forensics firm to determine impact on patient and employee data.

The healthcare organization did not provide specific details on the type of cyberattack it suffered and it appears that file-encrypting malware was not deployed on its systems. According to the LockBit ransomware gang, only data exfiltration occurred.

“We purposely didn’t encrypt this hospital so as not to interfere with patient care,” the gang notes on its Tor-based leak site.

The ransomware group says it stole more than 10 million files from the healthcare organization, which allegedly includes medical confidentiality data.

The cybercriminals also note that they have only compromised the Capital Health Regional Medical Center, a Trenton, New Jersey-based member of the Capital Health system.

Advertisement. Scroll to continue reading.

The LockBit group added Capital Health to its leak site on January 7, threatening to make the allegedly stolen information public today, unless a ransom is paid. The gang claims that the stolen data is worth roughly $250,000.

In 2023, tens of millions of individuals in the US were impacted by data breaches at healthcare providers and their business partners. Some of the most impactful incidents were disclosed by HCA Healthcare, HealthEC, the Colorado Department of Health Care Policy and Financing (HCPF), ESO Solutions, McLaren Health Care, Point32Health, Tampa General Hospital, and NextGen Healthcare.

Related: CISO Conversations: Three Leading CISOs in the Modern Healthcare Sector

Related: CISA, HHS Release Cybersecurity Healthcare Toolkit

Related: CISA Flags Gaps in Healthcare Org’s Security Posture, Issues Security Guidance

Written By

Ionut Arghire is an international correspondent for SecurityWeek.


Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Gain valuable insights from industry professionals who will help guide you through the intricacies of industrial cybersecurity.


Join us for an in depth exploration of the critical nature of software and vendor supply chain security issues with a focus on understanding how attacks against identity infrastructure come with major cascading effects.


Expert Insights

Related Content


The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...


Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.


Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.


A SaaS ransomware attack against a company’s Sharepoint Online was done without using a compromised endpoint.

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

CISO Strategy

Okta is blaming the recent hack of its support system on an employee who logged into a personal Google account on a company-managed laptop.


Several major organizations are confirming impact from the latest zero-day exploits hitting Fortra's GoAnywhere software.