CSIDB logo
Incident

Ferguson Medical Group

Incident posture

Attack window
Sep 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-22 00:00

Linked entities

Victim
Ferguson Medical Group
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack targeted Ferguson Medical Group prior to its acquisition, rendering pre-acquisition medical records inaccessible. The parent organization declined ransom demands, collaborating with law enforcement and restoring partial data from backups; unrecoverable records included specific service periods and scanned documents. While no unauthorized data disclosure was confirmed, precautionary notifications and complimentary credit monitoring were provided to potentially affected individuals, alongside a dedicated support call center.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 20, 2019, Ferguson Medical Group (FMG) in Sikeston, Missouri, experienced a ransomware attack on its computer network. Saint Francis Healthcare System, which had acquired FMG prior to the incident, discovered the attack on September 21, 2019. The attack rendered all medical records for services provided at FMG before January 1, 2019, inaccessible. Attackers demanded payment to restore access to the encrypted records. Saint Francis immediately secured the compromised network and collaborated with federal law enforcement agencies throughout their response. The organization declined to pay the ransom, opting instead to restore data from backup files. Restoration efforts proved incomplete, leaving certain records permanently unrecoverable.

Medical records spanning September 20, 2018, to December 31, 2018, along with all documents scanned into FMG’s system regardless of their creation date, could not be restored from backups. Saint Francis found no evidence that patient information was disclosed to unauthorized third parties or misused. The healthcare system initiated patient notifications by mail on November 20, 2019, advising precautionary measures despite assessing no actual data misuse. Impacted individuals received offers for complimentary credit monitoring services accessible via mailed instructions or a dedicated toll-free call center. Saint Francis established the call center (866-611-1186) operating Monday through Friday from 8 am to 8 pm Central Time to address patient inquiries. The organization expressed regret for the incident while emphasizing its commitment to patient care and information security.

Sources

Sources available to members: 1 source.

CSIDB