U.S. Hospital Pays $55,000 to Hackers After Ransomware Attack
Hancock Health has paid hackers $55,000 to unlock systems infected with ransomware that demanded a ransom in Bitcoin, as reported on the following page:
https://www.zdnet.com/article/us-hospital-pays-55000-to-ransomware-operators/
The Greenfield, Ind.-based hospital revealed that a successful ransomware attack on Thursday had held the hospital’s IT systems hostage, demanding a ransom payment in Bitcoin (BTC) in exchange for the ransomware decryption key.
Hancock Health Chief Strategy Officer (CSO) Rob Matt said in a statement that the attack occurred around 9:30 a.m., and while employees immediately recognized the malware, it was too late to prevent the virus from spreading to the hospital’s email, electronic health records, and internal operating systems. According to local media, the ransomware operators behind the attack targeted over 1,400 files and renamed them “I’m sorry” as part of the attack.
Hancock Health CEO Steve Long believes the hackers are based in Eastern Europe, gaining access to the hospital’s systems by logging into Hancock Hospital’s remote access portal using third-party vendor credentials. The system was then infected with SamSam Ransomware. This specific type of malware targets vulnerable servers and, once installed on one machine, spreads to others on the same network.
Long said that while backups could be used to restore infected systems and files encrypted by the ransomware, it might take “days, perhaps even weeks,” to restore the systems. Meanwhile, the hospital was given seven days to pay to decrypt files that were permanently encrypted and inaccessible.
This ransomware can be deployed via web shells, batch scripts to run malware on multiple machines, remote access, and tunneling. When a business pays such a ransom, they not only fund further ransomware operations but also take a risk. The promised decryption key may not be provided or may not work, leaving the victim out of pocket and still without access to their files. However, in this case, after Hancock Health paid, the hackers provided a working decryption key as soon as they received the payment they demanded.
“Through the effective teamwork of Hancock’s technology team, a group of expert technology consultants, and our clinical team, Hancock was able to restore computer access, and currently, there is no evidence that any patient information was compromised,” according to a statement from Hancock Health.
Recent Articles
-
Cloudmatika / July 17, 2026
How to Install and Configure an SSL Certificate on Windows Server and IIS
-
Cloudmatika / March 30, 2026
Tier 3 Data Center for Stable Business Operations
-
Cloudmatika / March 30, 2026
Cyber Protect for the Digital Industry: Strategies for Protecting Data, Systems, and Business Operations
-
Cloudmatika / March 26, 2026
Save Costs with Containers in a Virtual Data Center
-
Cloudmatika / March 26, 2026
Zimbra Email & Collaboration for Cost Efficiencies
