Maze
Incident posture
Timeline
Summary
Ventura Orthopedics was compromised by ransomware attackers who added the organization to a leak site and claimed to have exfiltrated a portion of its files. The Maze ransomware group posted an archive allegedly representing five percent of the stolen data, while a separate leak site associated with Conti‑Ryuk published approximately eighteen hundred files, including patient names, dates of birth, medication lists and laboratory results. The exposed filenames revealed protected health information without opening the documents. No public statement was issued by the victim and there is no indication that a ransom was paid.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On August 2, 2020, the cybersecurity firm Cyble tweeted that the Maze ransomware group had added Ventura Orthopedics to its leak site and had uploaded an archive of files allegedly taken from the practice’s server. The tweet included a link to the archive and the actors claimed that the uploaded material represented approximately five percent of the total data they had exfiltrated. No public statement was issued by Ventura Orthopedics at that time, and the organization’s website and the HHS breach reporting tool showed no additional information about the incident. The tweet was the first public indication that the practice had been targeted by a ransomware operation.
Later, DataBreaches.net became aware that the Conti‑Ryuk ransomware group had also created a leak site that listed Ventura Orthopedics as one of its victims. Conti‑Ryuk published approximately 1,850 files taken from the orthopedic practice’s systems. While some of the published files did not contain patient‑specific information, a substantial number consisted of patients’ records, including laboratory and diagnostic reports from RX Diagnostic Management, Inc. Those reports exposed individuals’ names, dates of birth, prescribed medications, and laboratory findings or results. The mere listing of the files revealed protected health information because the practice used a filename convention of lastname_first2lettersoffirstname_DOB(yyyy/mm/dd).
Ventura Orthopedics had reportedly implemented proactive backup measures, which helped limit the overall impact of the attack. According to the source, the attack did cause some disruption but could have been far worse given the organization’s preparedness. DataBreaches.net attempted to obtain a comment from Ventura Orthopedics by contacting the practice directly and later through Chris Roberts of the HillBilly Hit Squad, who was conducting forensic analysis on behalf of the organization. Roberts indicated that he was still completing the forensic investigation and would share a fuller picture of the incident once his work was finished. The Maze leak site did not disclose any collaboration with Conti‑Ryuk, leaving unclear which ransomware variant was actually deployed and how any potential ransom would have been divided between the groups. The available information indicates that no ransom payment was made in connection with this incident.
As of the date of the article, Ventura Orthopedics had not provided a public statement or additional details about the ransomware attack, the data exfiltration, or the steps taken to secure its systems. DataBreaches.net noted that the post would be updated if a response from the practice or further forensic findings became available. The incident remains documented by the leak site disclosures and the initial tweet from Cyble, which together outline the timeline of the attackers’ actions and the nature of the data that was exposed.
Sources
Sources available to members: 1 source.