Menu
Browse

Cyber Incident Victim: Cone Health

Date:

Oct 2020

Location:

United States of America

Summary

A Greensboro-based health system's medical practice, Alamance Skin Center, experienced a ransomware attack following unauthorized system access via a phishing scam or brute force method. The incident disrupted operations and compromised the center's network, though specific data impacts were not detailed in available reports. The attack targeted the Burlington-located facility affiliated with Cone Health, highlighting vulnerabilities in healthcare cybersecurity infrastructure.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On October 21, 2020, Alamance Skin Center, a medical practice affiliated with Greensboro-based Cone Health, experienced a ransomware attack. The attackers compromised the system through either a phishing scam or brute force attack, though the specific initial vector remained unspecified in public disclosures. The incident disrupted operations at the Burlington-based dermatology practice, though the exact duration and scope of operational impact were not detailed in available reports. Cone Health publicly confirmed the attack within the same week it occurred, characterizing it as a targeted cyber intrusion. No further technical specifics regarding the ransomware variant, encryption methods, or attacker infrastructure were disclosed by the health system or its representatives.

Cyber Incident Image

Cone Health’s announcement did not specify whether patient data was accessed or exfiltrated during the breach, nor did it confirm if the attackers issued ransom demands. The health system did not publicly describe containment measures, recovery timelines, or whether law enforcement was engaged. The incident remained confined to Alamance Skin Center’s systems, with no indication of lateral movement to broader Cone Health networks. Public reporting did not address whether the practice restored operations via backups, paid a ransom, or implemented additional security measures post-incident. The attack highlighted vulnerabilities in regional healthcare infrastructure but yielded limited public documentation of its technical or financial consequences.

Sources
Sources available to members
1 source