/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Cybersecurity experts say FBI is investigating Ryuk ransomware attacks on more than two dozen US hospitals, and officials warned hospitals to back up systems

WASHINGTON (Reuters) - The FBI is investigating the recent targeting with ransomware of more than two dozen hospitals across …

Reuters Christopher Bing

Context & Ripple Effects

This October 2020 alert lands mid-campaign rather than at its start: Ryuk had already struck more than 235 US hospitals since 2018, collecting an estimated $100M in ransoms the year before, so the FBI investigation of a fresh cluster of two dozen-plus attacks is an escalation of a known pattern, not a new threat. The official guidance — back up your systems — is telling: with law enforcement unable to interdict the gang, resilience is being pushed down to individual hospital IT teams.

The story also previews how Washington would respond going forward. The FBI director would later describe tracking roughly 100 ransomware strains, many tracing back to Russia, as a challenge comparable to 9/11, and subsequent advisories — from the FBI-CISA-Treasury warning on North Korea's Maui ransomware in healthcare to the Prospect Medical Holdings investigation — show hospitals becoming a standing target set for both criminal and state-linked crews.

First-order effects

  • More than two dozen US hospitals are operating under active ransomware attack while the FBI investigates, forcing them to weigh downtime against paying Ryuk for decryption.
  • Federal officials' directive to back up systems shifts the immediate burden of defense onto hospital IT staff, making offline backups the difference between a recoverable incident and a shutdown.

Second-order effects

  • Hospitals that restore from backups instead of paying undercut Ryuk's revenue model, pressuring the gang toward softer targets or higher demands on victims without resilient copies.
  • Healthcare systems nationwide face pressure to fund segmentation, immutable backups, and incident planning, since the guidance effectively designates unprepared providers as the next victims.

Third-order effects

  • If the pattern holds, hospitals become permanent critical-infrastructure targets for both criminal groups like Ryuk and state-backed crews — a trajectory confirmed by later advisories on Maui and Ghost ransomware hitting the sector.
  • US cyber policy consolidates around a repeatable playbook — FBI investigation, CISA joint advisory, Treasury sanctions exposure — with resilience ('recovery by design') treated as the primary control when attribution and takedowns lag.

The trend: Ransomware is evolving from opportunistic extortion into sustained campaigns against critical infrastructure, with hospitals as a recurring target and federal agencies responding through investigations and joint advisories rather than prevention alone.

Discussion

  • @cisakrebs @cisakrebs on x
    🚨🚨🚨 Healthcare and Public Health sector partners - shields up! Assume Ryuk is inside the house. Executives - be ready to activate business continuity and disaster recovery plans. IT sec teams - patch, MFA, check logs, make sure you have a good backup point. https://twitter.com/..…
  • @bymikebaker Mike Baker on x
    Russian hackers are targeting hundreds of U.S. hospitals and claim to have already hit some of them. Officials and researchers have identified problems at medical centers in California, New York and Oregon. https://www.nytimes.com/...
  • @andreachalupa Andrea Chalupa on x
    Russia is attacking hundreds of hospitals across the US during a pandemic, delaying surgeries, rerouting ambulances. For Russia, cruelty is power. Just ask Ukraine, the Syrian people, Venezuelans dying in a famine under a dictator propped up by Russia, etc https://www.nytimes.com…
  • @briankrebs @briankrebs on x
    FBI, DHS, HHS warn of “imminent,” “credible” ransomware threat against U.S. hospitals. One source said the Ryuk ransomware gang is targeting more than 400 hospitals, clinics and medical care facilities. https://krebsonsecurity.com/ ...
  • @maddowblog @maddowblog on x
    ""We expect panic," one hacker involved in the attacks said in Russian during a private exchange on Monday that was captured by Hold Security, a security company that tracks online criminals." https://www.nytimes.com/...
  • @arawnsley Adam Rawnsley on x
    100% ok with making people who ransomware hospitals in the middle of a pandemic spend eternity in prison. https://twitter.com/...
  • @agoodfireburns @agoodfireburns on x
    Really wouldn't take much to destroy the Western world right now. This would be an easy route to doing just that. NotPetya was peacetime and it caused chaos. https://twitter.com/...