Scripps Hackers
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor identified as Scripps Hackers is known to operate from the United States of America. Open‑source reports first linked the alias to a cyber incident on May 1 2021. The target of that operation was Scripps Health, a healthcare provider based in southern California. The sector affected by the attack is the healthcare industry, which manages patient records and clinical services. The malicious activity deployed ransomware that encrypted critical IT systems within the organization. As a result, Scripps Health’s online patient portals were taken offline and could not be accessed by users. Internal networks that support clinical workflows also became unavailable during the incident. The encryption prevented staff from retrieving electronic medical records in real time. The disruption extended to scheduling systems, leading to the postponement of non‑urgent appointments across the facility network. Emergency and urgent care units remained functional by switching to paper‑based documentation. Law‑enforcement authorities were notified and began an investigation shortly after the outage was detected.
During the outage, access to medical imaging services was compromised, delaying diagnostics for patients who required scans. Electronic monitoring of vital signs in multiple hospital units was impaired, necessitating manual checks by clinical staff. Patients experiencing stroke symptoms were redirected to neighboring hospitals capable of providing immediate intervention. Similar diversion procedures were applied to individuals presenting with heart‑attack symptoms to ensure timely treatment. While electronic systems were offline, Scripps Health continued to deliver essential urgent care using printed forms and handwritten notes. The organization reported that it worked continuously to restore operations, rebuilding the affected IT environment from backups. Standard patient‑portal functionality was gradually reinstated once systems were verified as clean and operational. Public sources do not indicate whether a ransom payment was made or if a decryption key was obtained from the attackers. The incident is cited as an example of ransomware impacting critical healthcare infrastructure in the United States.
Incidents
Attributed incidents are available to members.
1 incident