CSIDB logo
Incident

Faben Obstetrics and Gynecology

Incident posture

Attack window
Nov 2018
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-26 00:00

Linked entities

Victim
Faben Obstetrics and Gynecology
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Florida-based obstetrics and gynecology practice experienced a ransomware attack involving GandCrab malware, leading to rapid detection and mitigation efforts that included deleting infected files and restoring from backups. Not all files were recoverable due to incomplete backups, particularly impacting manually scanned patient documents such as lab reports. The incident resulted in unauthorized access to protected health information, prompting notifications to over 6,000 affected patients and reporting to federal health authorities.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On November 21, 2018, Faben Obstetrics and Gynecology (FABEN OB/GYN), a medical practice in Florida, experienced a ransomware attack involving the GandCrab variant. The infection was detected rapidly by the organization, though the specific intrusion method or initial attack vector was not publicly disclosed. In response to the encryption of files, Faben implemented containment measures by deleting the compromised data and restoring systems from backup repositories. This restoration process revealed gaps in their backup coverage, as manually scanned patient documents—such as externally provided lab results or medical reports—were not included in the preserved backups. The practice did not confirm whether it attempted file decryption or engaged with threat actors regarding ransom demands.

The incident potentially exposed personal health information from manually scanned records that could not be recovered through backups. Faben formally reported the breach to the U.S. Department of Health and Human Services (HHS), indicating 6,092 affected patients. Patient notifications commenced by January 14, 2019, though the notification did not specify whether data exfiltration occurred prior to encryption. While a free decryption tool for certain GandCrab versions existed by early November 2018, Faben did not disclose whether their infection involved a decryptable variant or if they utilized available tools. The ransomware’s impact centered on operational disruption during restoration and permanent loss of unsupported patient records, with no additional details provided regarding financial losses, legal actions, or long-term recovery measures beyond the initial response.

Sources

Sources available to members: 1 source.

CSIDB