HomeNews UpdateAlleged boss of global healthcare hacker group arrested

Alleged boss of global healthcare hacker group arrested

Dutch authorities have arrested an alleged leader of ShinyHunters, the cybercriminal group that has targeted global healthcare organisations and their third-party vendors – and which also recently breached confidential FBI staff and healthcare record data – reports Becker’s Hospital Review.

The Dutch National Police’s High Tech Crime Unit arrested the suspect under Dutch law with the FBI’s support, said Brett Leatherman, assistant director of the FBI’s Cyber Division. The suspect, who is apparently 24, was not named.

Since last year, the suspect and co-conspirators have allegedly breached more than 140 organisations in The Netherlands, the US and other countries, and collected at least $70m in extortion payments.

The group often targets third-party vendors on cloud-based platforms, stealing sensitive data and threatening to publish it.

On Tuesday, in an unusually public request to ShinyHunters, Leatherman told the cybercriminals they should get in touch – this after the wide-ranging breach of the bureau’s job site. FBI personnel data stolen by the hackers includes sensitive psychiatric and medical evaluation records.

ShinyHunters had circulated the medical files to a small circle of reporters earlier this week after announcing it had broken into the FBIjobs.gov site and stolen what it claimed was 2 to 3 terabytes of data.

Last week the BBC reported that a blood and urine test document  was among the samples, but the presence of other sensitive files, including a mental health evaluation and other records, has not previously been reported.

Reuters was able to partially authenticate some of the half-dozen files in several ways, including running two social security numbers in them against credit bureau data, and lining up the date of a pre-employment mental health evaluation against a former FBI analyst’s LinkedIn profile.

Reuters also matched the name of an FBI psychiatrist in the document to a LinkedIn profile with the same name and an identical job title.

In a video address on Tuesday, posted on X, Leatherman said the arrest of one of the hackers should serve as a warning.

He told the remaining members of the group that arrests “tend to change who is willing to talk to investigators”.

“Other groups believed anonymity, or their friends, would protect them, and they were wrong,” he said.

Last month the Health Information Sharing and Analysis Centre had warned that ShinyHunters was using targeted voice phishing campaigns to trick personnel into entering credentials on malicious, medical-themed impersonation domains.

The group has contacted employees directly on personal devices through calls, voicemails and emails from multiple accounts.

“ShinyHunters is currently one of the most prolific and aggressive cybercriminal groups targeting healthcare and third-party healthcare vendors,” said the American Hospital Association’s John Riggi, national advisor for cybersecurity and risk at the AHA.

 

Becker’s Hospital Review article – Alleged ShinyHunters leader arrested; group targeted healthcare (Open access)

 

Reuters article – ShinyHunters hackers say they stole psychiatric and medical records of FBI staff (Open access)

 

FBI official tells hackers to get in touch, says 'we know how to find you' (Open access)

 

See more from MedicalBrief archives:

 

FBI flags new hackers targeting health

 

Cyber attacks create havoc in state hospitals in SA, and globally

 

Cyber thieves post patients' data stolen from Australian medical insurer

MedicalBrief — our free weekly e-newsletter

We'd appreciate as much information as possible, however only an email address is required.