Menu
Browse

Cyber Incident Victim: SERV Behavioral Health System

Date:

May 2022

Location:

United States of America

Summary

SERV Behavioral Health System experienced a ransomware attack allegedly conducted by the Hive group, resulting in file encryption and subsequent listing on the threat actor's leak site following unmet ransom demands. The organization did not publicly confirm or deny the breach despite multiple inquiries, and no regulatory notifications or consumer disclosures were verified at the time of reporting. Hive provided no evidence of data exfiltration, though unconfirmed speculation suggested potential exploitation of an unpatched legacy email server prior to migration to a cloud environment. Job listings indicated employee HIPAA training requirements, but no official breach report appeared on federal databases.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On May 26, 2022, SERV Behavioral Health System, a New Jersey-based provider of social, educational, residential, and vocational services for individuals with mental illness or developmental disabilities, allegedly experienced a ransomware attack. The Hive ransomware group claimed responsibility for encrypting the organization’s files. Despite the encryption event, SERV did not publicly acknowledge the incident or respond to multiple inquiries from DataBreaches.net sent on July 14 and August 3. On July 14, Hive listed SERV Behavioral Health System on its data leak site, suggesting the organization did not meet ransom demands. The ransomware group did not provide a "proof pack" to validate its claims or disclose the volume or nature of exfiltrated data, leaving the scope of potentially compromised information unverified.

Cyber Incident Image

SERV’s lack of public response extended to regulatory and client notifications, with no entry found in the U.S. Department of Health and Human Services’ breach reporting tool as of August 6, 2022. While SERV’s HIPAA compliance status remained unclear, job listings indicated employees underwent HIPAA training, implying potential handling of protected health information. An external security researcher suggested a possible attack vector involving an unpatched on-premises Microsoft Outlook Web Access (OWA) server (exchange.servbhs.org), which was accessible in May 2022 before its services migrated to Microsoft Office 365. This migration coincided with the alleged attack timeline but was not confirmed by SERV. The absence of official statements left the incident’s operational, legal, and client impacts undocumented, including whether data exposure occurred or remediation steps were taken.

Sources
Sources available to members
1 source