Menu
Browse

Cyber Incident Victim: McKenzie Health System

Date:

Apr 2022

Location:

United States of America

Summary

McKenzie Health System experienced a ransomware attack by the Avos Locker group, which resulted in the compromise of protected health information, including health insurance details. The attackers listed the organization on their leak site and provided limited proof of data exfiltration, though the extent of the breach was initially unclear. The incident impacted 25,318 individuals, prompting mandatory reporting to federal authorities and notification to affected patients. The organization’s public disclosure did not reference the ransomware involvement or confirm whether attackers had already leaked stolen data.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On or around April 7, 2022, Avos Locker ransomware operators claimed responsibility for an attack on McKenzie Health System, a Michigan-based healthcare provider. The group listed the organization on their data leak site, providing limited proof of claim that included at least one file containing health insurance information, which constitutes protected health information (PHI). The evidence presented by the attackers did not strongly demonstrate acquisition of substantial sensitive data. McKenzie Health System had no public statements regarding the incident on its website at the time of initial reporting and did not respond to inquiries from DataBreaches.net seeking confirmation or denial of the breach. This lack of public acknowledgment persisted for over a month following the ransomware group's disclosure.

Cyber Incident Image

McKenzie Health System eventually reported the incident to the U.S. Department of Health and Human Services (HHS) on May 10, 2022, disclosing that the breach affected 25,318 patients. The organization mailed notification letters to impacted individuals and published a notice on its website the same day as the HHS filing. McKenzie's public notice omitted any reference to ransomware involvement or prior data exfiltration by threat actors, despite Avos Locker's earlier leak site publication. The compromised data included PHI in the form of health insurance information, though the full scope of accessed records remained unspecified in available disclosures. No operational disruptions or system restoration timelines were detailed in McKenzie's communications, nor did the organization confirm whether any data was actually published by the attackers following their initial leak site posting.

Sources
Sources available to members
1 source