Health IT Security October 24, 2022
The Daixin Team ransomware group has been observed encrypting healthcare servers and exfiltrating protected health information, the FBI, HHS, and CISA stated.
The Daixin Team ransomware and data extortion group is an active threat to the healthcare sector, The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and HHS warned in a cybersecurity advisory (CSA).
The group has been active since at least June 2022 and has executed multiple attacks against the healthcare sector. Specifically, the group has deployed ransomware to encrypt servers that are essential to healthcare, such as EHR systems, diagnostic services, and imaging services.
In addition, the group has been known to exfiltrate protected health information (PHI) and hold it for ransom.