U.S. federal agencies warned that hospitals and healthcare providers faced an imminent and credible ransomware threat as multiple organizations were already dealing with disruptive intrusions linked to the Ryuk ecosystem. The joint alert from CISA, the FBI, and HHS said the healthcare and public health sector was being actively targeted, while reporting indicated threat actors had discussed deploying ransomware across hundreds of U.S. healthcare facilities.
Several hospitals reported operational impacts consistent with the campaign, including St. Lawrence Health System in New York and Sky Lakes Medical Center in Oregon, while the University of Vermont Health Network disclosed a major network outage under investigation as a possible cyberattack. Security researchers and incident responders tied the activity to Ryuk and associated operators, describing it as a significant escalation that disrupted hospital systems, forced some patient diversions, and raised concern that additional healthcare organizations could be hit.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
BleepingComputer reported that Wyckoff Hospital in New York was hit by a Ryuk ransomware attack. The incident was one of the specific hospital compromises cited during the broader healthcare-sector campaign.
CNN reported that hospitals in New York, Nebraska, Ohio, Missouri, and Michigan had been attacked by some form of ransomware since July. This established a broader backdrop of healthcare-sector targeting before the late-October wave.
Alex Holden said Ryuk-affiliated criminals discussed plans to deploy ransomware at more than 400 U.S. healthcare facilities, and Mandiant tracked the responsible cluster as UNC1878. Mandiant also released domains and IP addresses associated with Ryuk activity during 2020 and described multiple hospitals as already significantly impacted.
Federal agencies publicly warned of ransomware activity targeting the Healthcare and Public Health Sector, describing an increased and imminent threat to U.S. hospitals and healthcare providers. The alert accompanied an active federal investigation into the attacks.
The FBI, DHS, and HHS held a conference call with healthcare industry executives and said they had credible information about an increased and imminent cybercrime threat to U.S. hospitals and healthcare providers. Participants said the agencies urged precautions but shared few concrete defensive details or indicators of compromise.
Mandiant said it identified at least three attacks on Tuesday and one on Wednesday, while Recorded Future knew of at least six attacks in the prior 24 hours. The attacks were severe enough to force some hospitals to divert patients to other providers.
The University of Vermont Health Network said it was dealing with a significant and ongoing system-wide network issue and was investigating whether it was caused by a malicious cyberattack. The outage was included among the healthcare incidents unfolding during the warning period.
Ridgeview Medical Center in Minnesota reported unidentified network activity that disrupted certain operations. The facility was cited as another contemporaneous healthcare organization experiencing suspicious cyber-related disruption.
Sky Lakes Medical Center in Oregon confirmed that its computer systems were hit in the same late-October wave. The incident was cited by multiple reports as one of the hospitals already affected.
St. Lawrence Health System in New York said it had been targeted over the previous few days, and reporting cited Ryuk infections affecting hospitals in Potsdam, Massena, and Gouverneur. The health system said the malware was a new Ryuk variant previously unknown to antivirus providers and security agencies.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
krebsonsecurity.com
Open sourceedition.cnn.com
Open sourceus-cert.cisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.