DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Lake Charles Memorial Health system victim of cyberattack and data leak by Hive

Posted on November 16, 2022 by Dissent

On October 25, Lake Charles Memorial Health System (LCMH) in Louisiana received an email that began, “Ladies and gentlemen! Attention, please!  This is Hive Ransomware Team.” The remainder of the email stated that Hive had been in LCMH’s network for 12 days and had exfiltrated 270 GB of files including patient and employee data. A sample of files was attached to the email as proof of claims, and Hive also commented on what they had found (typos as in the original):

We know about your planned Splunk SIEM Product Justification Meeting. This system will not help to protect your network. It will only make a slightly delay in next data breach your network will face. Our organisation is also offers you full information about weak spots in your networks and best ways to protect your business to prevent further hack attacks, information we can share will help you to make such breaches economically disadvantageous for big hacking organisations and “very hard to do” for small ones.

Copies of the correspondence between Hive and LCMH and files were shared exclusively* with DataBreaches.net. On inquiry, Hive’s spokesperson stated that they had not encrypted any of LCMH’s files, but had just exfiltrated them. They also informed DataBreaches that in addition to emailing LCMH, they had called them on the phone. Multiple inquiries sent to LCMH executives during the last week of October by DataBreaches received no reply.

On November 15, Hive provided DataBreaches with an email chain between Hive and LCMH and added LCMH to their dedicated leak site. Hive’s leak site notice did not provide any proof pack yesterday, but did start leaking data publicly today.

The email chain indicates that on October 27, someone using a protonmail account had responded to Hive’s email of October 25 and claimed to be a managing director with LCMH. A search of their name by DataBreaches finds no such employee by that name. A person by the same name is a system administrator in Texas, however.

Over the next days, Hive sent LCMH’s negotiator a file list as LCMH requested and more information. According to the correspondence provided to DataBreaches, Hive demanded $900,000 to delete all files and provide them with information on their vulnerabilities. DataBreaches did not see any email from LCMH indicating that LCMH ever tried to make a counteroffer at all.

On November 3, LCMH’s negotiator confirmed they had received some files they had requested as proof, adding, “We are discussing everything with our mid to upper management. We will have to get our board to convene a meeting to brief them on everything in the next few days so they can make a decision on how we should proceed.” When pushed by Hive as to when this would all happen, they replied on November 4 (typos as in the original):

The board will be convening next Friday. One week from today. We been instructed to review the data loss impact and the budget until them so we can present them with our findings and recommendation. With payment you will disclose the vulnerabilities to us that you used to access our network?

By then, Hive appeared to have come to the conclusion that LCMH was just stalling. There were a few more back-and-forth emails on November 7, and then nothing more from LCMH. LCMH did not contact Hive after November 7 and did not respond to any subsequent emails from Hive.

As of the time of publication, DataBreaches has not seen all the data Hive claims to have acquired and that they threaten to leak, and has not yet reviewed all of the data that they have already leaked, but it is clear that the leak does include protected health information on patients, such as a folder with 5,834 files for patients using the mammography service in 2022.  Other folders contain internal documents, such as files relating to a previous HIPAA breach inquiry, and yet other folders and files contain personnel information on employees. Among the files in the leak, DataBreaches noted files containing personnel information that could be useful for phishing or socially engineering LCMH’s security personnel, and a folder with 664 files on individual employees with their personal and personnel information.

DataBreaches did not spot any patient databases or human resources databases at this time and it is not clear that Hive was able to access or exfiltrate those databases.  This post will be updated as DataBreaches is able to review other folders in the leak that are not currently accessible.

For its part, LCMH, who discovered the breach on October 25, has yet to respond to inquiries or to post any notice or alert to patients on its website.

*Update: It appears that Hive has  now reached out to all local media in Louisiana with details and the chat negotiations.


Related:

  • PowerSchool commits to strengthened breach measures following engagement with the Privacy Commissioner of Canada
  • Two more entities have folded after ransomware attacks
  • Data breach feared after cyberattack on AMEOS hospitals in Germany
  • Microsoft Releases Urgent Patch for SharePoint RCE Flaw Exploited in Ongoing Cyber Attacks
  • Global hack on Microsoft product hits U.S., state agencies, researchers say
  • Michigan ‘ATM jackpotting’: Florida men allegedly forced machines to dispense $107K
Category: Breach IncidentsHackHealth DataU.S.

Post navigation

← Medibank defends decision to not pay hackers ransom for stolen data as it contacts 480,000 customers
To Detail or Not: The Breach Notification Conundrum →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Paying cyberattackers is wrong, right? Should Taos County’s incident be an exception?
  • HHS OCR Settles HIPAA Ransomware Investigation with Syracuse ASC for $250k plus corrective action plan
  • IVF provider Genea notifies patients about the cyberattack earlier this year.
  • Key figure behind major Russian-speaking cybercrime forum targeted in Ukraine
  • Clorox Files $380M Suit Alleging Cognizant Gave Hackers Passwords in Catastrophic 2023 Cyberattack
  • Cyberattacks Paralyze Major Russian Restaurant Chains
  • France Travail: At least 340,000 job seekers victims of new hack
  • Legal Silence and Chilling Effects: Injunctions Against the Press in Cybersecurity
  • #StopRansomware: Interlock
  • Suspected XSS Forum Admin Arrested in Ukraine

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Meta Denies Tracking Menstrual Data in Flo Health Privacy Trial
  • Wikipedia seeks to shield contributors from UK law targeting online anonymity
  • British government reportedlu set to back down on secret iCloud backdoor after US pressure
  • Idaho agrees not to prosecute doctors for out-of-state abortion referrals
  • As companies race to add AI, terms of service changes are going to freak a lot of people out. Think twice before granting consent!
  • Uganda orders Google to register as a data-controller within 30 days after landmark privacy ruling
  • Meta investors, Zuckerberg reach settlement to end $8 billion trial over Facebook privacy violations

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.
Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report