bike rider passes 'NHS' in large white letters on blue wall


U.Okay. healthcare big HCRG Care Group has confirmed it’s investigating a cybersecurity incident after a ransomware gang claimed to have breached the corporate’s methods to steal troves of delicate knowledge. 

HCRG Care Group is among the largest impartial suppliers of neighborhood well being and care companies in the UK. The group, beforehand referred to as Virgin Care and now owned by Twenty20 Capital, companions with Nationwide Well being Service trusts and native authorities across the U.Okay. to ship healthcare companies, together with pressing care, sexual well being, and grownup and baby social care companies.

HCRG was this week listed on the darkish internet leak website of the prolific Medusa ransomware group, which claims to have compromised the corporate to steal greater than two terabytes of knowledge. 

Samples of the allegedly stolen knowledge shared by Medusa and seen by TechCrunch seem to incorporate workers’ private info, delicate medical data, monetary data, and authorities identification paperwork, reminiscent of passports and delivery certificates.

HCRG spokesperson Alison Klabacher informed TechCrunch in an emailed assertion that the corporate is “at the moment investigating an IT safety incident” and has “just lately recognized a publish on the darkish internet by a gaggle claiming accountability.”

The corporate declined to say what forms of knowledge have been accessed however didn’t dispute Medusa’s claims. HCRG additionally declined to say what number of people are affected. In response to the corporate’s web site, HCRG has greater than 5,000 workers and delivers healthcare companies to half 1,000,000 sufferers throughout the UK.

“Our group has not noticed any suspicious exercise because the implementation of fast containment measures, and we’re working with exterior forensic specialists to research the incident, the spokesperson stated. 

HCRG stated it knowledgeable the U.Okay.’s Data Commissioner’s Workplace and different regulators in regards to the breach.

“Our companies are persevering with to function and safely see sufferers, and people with appointments or who must entry our companies ought to proceed to take action,” the corporate stated.

The Medusa ransomware group is threatening to publish the allegedly stolen knowledge except HCRG pays the gang a ransom demand of $2 million.

HCRG wouldn’t verify the way it was compromised, however Medusa is understood to take advantage of unpatched vulnerabilities in distant desktop software program.