Menu
Browse

Cyber Incident Victim: Planned Parenthood of Montana

Date:

Aug 2024

Location:

United States of America

Summary

Planned Parenthood of Montana experienced a cybersecurity incident involving unauthorized network access by the ransomware group RansomHub, which claimed theft of 93GB of data and issued extortion threats to leak the information unless paid. The organization proactively took portions of its network offline, engaged federal law enforcement, and mobilized cybersecurity experts to investigate the breach scope and restore systems, while acknowledging the attackers' claims but not confirming data compromise specifics. RansomHub has been actively targeting critical infrastructure sectors, including healthcare, as noted in recent federal alerts about the group's recruitment of former LockBit and ALPHV members and its rapid expansion since February.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On August 28, 2024, Planned Parenthood of Montana detected a cybersecurity incident involving unauthorized network access, prompting immediate activation of incident response protocols. CEO Martha Fuller confirmed the organization proactively took portions of its network offline to contain the intrusion and engaged IT staff, cybersecurity partners, and federal law enforcement to investigate the breach and restore systems. Concurrently, ransomware group RansomHub claimed responsibility for the attack, alleging theft of 93GB of organizational data and threatening to leak the information within seven days unless paid. Fuller acknowledged awareness of RansomHub's public extortion demands but declined to confirm the validity of their data theft claims or explicitly attribute the attack to the group. The nonprofit reported the incident to federal authorities, though the FBI had not publicly commented at the time of reporting.

Cyber Incident Image

The intrusion occurred one day before US government agencies issued an alert warning of RansomHub's aggressive targeting of victims through August 2024. Federal investigations indicated the group had compromised at least 210 victims since February 2024 across critical infrastructure sectors including healthcare, government services, and transportation, recruiting former LockBit and ALPHV ransomware gang members following law enforcement disruptions of those groups. Planned Parenthood's cybersecurity team worked continuously to assess the incident's scope and securely restore affected systems, with the investigation remaining ongoing as of the last public statement. No specific details regarding compromised patient data, operational disruptions, or financial impacts were disclosed by the organization. Fuller emphasized the nonprofit's commitment to supporting law enforcement's investigation while maintaining focus on restoring systems and protecting community interests.

Sources
Sources available to members
1 source