<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cyberattack Case Library: Healthcare &amp; Medical Sector Feed</title>
    <link>https://cybercaselibrary.com/sectors/healthcare/</link>
    <description>Targeted cyberattack dossiers, ransomware incidents, and regulatory enforcement affecting the healthcare industry.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:02:15 GMT</lastBuildDate>
    <atom:link href="https://cybercaselibrary.com/feeds/healthcare.xml" rel="self" type="application/rss+xml"/>
    
    <item>
      <title><![CDATA[Healthcare Incident: U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)]]></title>
      <link>https://cybercaselibrary.com/cases/sandworm-notpetya-olympic-destroyer/</link>
      <guid>https://cybercaselibrary.com/cases/sandworm-notpetya-olympic-destroyer/</guid>
      <description><![CDATA[Six Russian Main Intelligence Directorate (GRU) military officers charged with deploying the NotPetya wiper, Olympic Destroyer malware, KillDisk attacks against Ukrainian power grids, and cyberattacks targeting French elections.]]></description>
      <category><![CDATA[Healthcare & Life Sciences]]></category>
      <pubDate>Thu, 15 Oct 2020 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Healthcare Incident: U.S. v. Khoroshev et al. (LockBit Ransomware Operation)]]></title>
      <link>https://cybercaselibrary.com/cases/lockbit-ransomware-takedown/</link>
      <guid>https://cybercaselibrary.com/cases/lockbit-ransomware-takedown/</guid>
      <description><![CDATA[Comprehensive global law enforcement takedown (Operation Cronos) of LockBit ransomware infrastructure, unmasking creator Dmitry Khoroshev (LockBitSupp) and multiple active affiliates who extorted over $500 million from thousands of victims.]]></description>
      <category><![CDATA[Healthcare & Life Sciences]]></category>
      <pubDate>Tue, 07 May 2024 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Healthcare Incident: ALPHV / BlackCat Ransomware Attack on Change Healthcare]]></title>
      <link>https://cybercaselibrary.com/cases/alphv-blackcat-change-healthcare/</link>
      <guid>https://cybercaselibrary.com/cases/alphv-blackcat-change-healthcare/</guid>
      <description><![CDATA[Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.]]></description>
      <category><![CDATA[Healthcare & Life Sciences]]></category>
      <pubDate>Wed, 21 Feb 2024 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Healthcare Incident: U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-hladyr-fin7-carbanak/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-hladyr-fin7-carbanak/</guid>
      <description><![CDATA[Prosecution of senior leaders of the FIN7 transnational cybercrime syndicate who hacked into thousands of computer systems across the United States, stealing more than 20 million customer credit card records from restaurants and hospitality chains.]]></description>
      <category><![CDATA[Healthcare & Life Sciences]]></category>
      <pubDate>Tue, 27 Mar 2018 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Healthcare Incident: U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-park-jin-hyok-lazarus/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-park-jin-hyok-lazarus/</guid>
      <description><![CDATA[Department of Justice charges North Korean state-sponsored programmer with the 2014 Sony Pictures hack, the 2017 global WannaCry ransomware outbreak, and the $81 million Bangladesh Bank cyber heist.]]></description>
      <category><![CDATA[Healthcare & Life Sciences]]></category>
      <pubDate>Fri, 08 Jun 2018 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Healthcare Incident: U.S. v. Vachon-Desjardins (Netwalker Ransomware)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-vachon-desjardins-netwalker/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-vachon-desjardins-netwalker/</guid>
      <description><![CDATA[Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.]]></description>
      <category><![CDATA[Healthcare & Life Sciences]]></category>
      <pubDate>Wed, 16 Dec 2020 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Healthcare Incident: U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-seleznev-track2/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-seleznev-track2/</guid>
      <description><![CDATA[Prolific cybercriminal (Track2) who hacked into more than 500 small businesses and restaurants across the United States, stealing millions of credit card numbers and generating tens of millions of dollars in illicit sales on automated carding portals.]]></description>
      <category><![CDATA[Healthcare & Life Sciences]]></category>
      <pubDate>Thu, 03 Mar 2011 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Healthcare Incident: U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-witte-dunaev-trickbot/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-witte-dunaev-trickbot/</guid>
      <description><![CDATA[Key software developers and coders of the transnational Trickbot cybercrime group charged with infecting millions of victim computers with banking trojans and facilitating Conti/Ryuk ransomware deployments against hospitals.]]></description>
      <category><![CDATA[Healthcare & Life Sciences]]></category>
      <pubDate>Thu, 18 Feb 2021 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Healthcare Incident: U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-sikerin-polyanin-revil-affiliates/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-sikerin-polyanin-revil-affiliates/</guid>
      <description><![CDATA[International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.]]></description>
      <category><![CDATA[Healthcare & Life Sciences]]></category>
      <pubDate>Mon, 08 Nov 2021 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Healthcare Incident: MGM Resorts Cyberattack (Scattered Spider / ALPHV Vishing Ingress)]]></title>
      <link>https://cybercaselibrary.com/cases/mgm-resorts-scattered-spider/</link>
      <guid>https://cybercaselibrary.com/cases/mgm-resorts-scattered-spider/</guid>
      <description><![CDATA[Sophisticated social engineering and ransomware attack carried out by cybercrime collective Scattered Spider partnering with ALPHV/BlackCat, utilizing a 10-minute phone call to the Okta IT helpdesk to bypass MFA, hijack administrative privileges, and paralyze hotel reservations, digital keys, and casino slot machines.]]></description>
      <category><![CDATA[Healthcare & Life Sciences]]></category>
      <pubDate>Thu, 05 Oct 2023 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Healthcare Incident: Change Healthcare Ransomware Outage (ALPHV / BlackCat)]]></title>
      <link>https://cybercaselibrary.com/cases/change-healthcare-blackcat-ransomware/</link>
      <guid>https://cybercaselibrary.com/cases/change-healthcare-blackcat-ransomware/</guid>
      <description><![CDATA[Nationwide healthcare billing and pharmacy clearinghouse paralyzed by an ALPHV/BlackCat ransomware deployment. Threat actors gained initial access through an unmonitored Citrix portal server lacking multi-factor authentication, exfiltrating 6 terabytes of protected health data and forcing a 350 Bitcoin ($22 million) extortion payout amidst an estimated $3+ billion systemic recovery cost.]]></description>
      <category><![CDATA[Healthcare & Life Sciences]]></category>
      <pubDate>Wed, 21 Feb 2024 00:00:00 GMT</pubDate>
    </item>
  
  </channel>
</rss>