Unimed Brusque
Incident posture
Linked entities
- Victim
- Unimed Brusque
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A healthcare cooperative in Brusque, Santa Catarina, confirmed it was targeted by a cyberattack carried out by unknown hostile actors, which disrupted internal systems, patient communication channels, appointment scheduling, and exam authorizations. The organization initially issued a notice citing system instability before confirming the cause as a cybercrime incident, while continuing to offer alternative contact through WhatsApp and an 0800 hotline. Its IT teams contained the situation and restored full functionality to all services. The cooperative stated that no personal or sensitive data was identified as compromised and that preventive and corrective measures were applied immediately, reaffirming its commitment to data protection and service quality.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Unimed Brusque, a healthcare cooperative based in the city of Brusque in the state of Santa Catarina, Brazil, publicly confirmed that it had been the target of a cyberattack during the last week of January 2025. The confirmation came in the form of an official clarification note published on the organization's website on or around February 1, 2025, after the cooperative had initially communicated only that it was experiencing technical instabilities. According to the official note, hostile and unknown actors were responsible for the actions that generated performance impacts on the cooperative's internal systems, affecting communication channels with patients, appointment scheduling, and authorizations for exams. The cooperative did not disclose the nature of the incident, the specific attack vector employed by the threat actors, or whether additional digital environments beyond the initially impacted ones were affected.
The sequence of events began when Unimed Brusque issued its first public communication indicating that it was facing instabilities in its systems and in the channels used to communicate with patients, as well as in consultation and examination processes. During this initial period of disruption, the cooperative offered alternative contact channels, instructing patients to use a WhatsApp number (47 3251-2499) and a toll-free 0800 line (0800 648-2500) to handle scheduling and other inquiries. At this stage, the cooperative did not characterize the event as a cyberattack, instead describing it simply as system instability. This initial posture mirrored standard crisis communications practices for healthcare organizations dealing with technology disruptions, prioritizing patient service continuity over immediate disclosure of the underlying cause.
Following internal investigation and containment activities, the cooperative subsequently confirmed that the technical challenges were in fact the result of cybercriminal actions carried out by unknown hostile actors. The official statement emphasized that the situation had been promptly contained by the organization's Information Technology teams and that all services had returned to full operation. Despite the disruptions that affected multiple operational channels, the cooperative stated that it did not identify any compromise of personal or sensitive data belonging to patients, employees, or other stakeholders. The note further indicated that all preventive and corrective measures were adopted immediately following the incident and that the organization's security protocols were being continuously reinforced.
The scope of the impact during the incident encompassed the cooperative's primary digital communication channels, appointment scheduling systems, and examination authorization processes. These systems are central to the day-to-day operations of a healthcare provider, as they facilitate patient access to medical consultations, diagnostic procedures, and continuous care. The disruption of these channels forced the organization to rely on alternative, manual contact methods, including WhatsApp messaging and voice calls through the toll-free line, to maintain communication with its service population. The cooperative did not report whether clinical care itself, such as in-person consultations, emergency services, or hospital procedures, was directly impacted by the systems outage, nor did it detail the duration of the disruption beyond noting that services had resumed normal operation by the time of the official confirmation.
In response to the incident, Unimed Brusque activated its Information Technology teams to contain the event, a process that the cooperative described as prompt and effective. The organization also established direct communication channels with its patients, publishing notices about the operational status and providing alternative contact information. Following the containment, the cooperative committed to the continuous reinforcement of its security protocols, although it did not specify which particular protocols had been enhanced or whether any external cybersecurity firms had been engaged to assist in the investigation or remediation efforts. The cooperative designated its Data Protection Officer channel, accessible via the email address [email protected], as the official point of contact for additional information regarding the incident. The note concluded by reaffirming the cooperative's commitment to data protection and the quality of services provided to its members.
The broader context of this incident places Unimed Brusque within a pattern of cyberattacks targeting the Brazilian healthcare sector and the Unimed cooperative network specifically. The healthcare sector globally remains one of the primary targets for cybercrime due to the financial and social impact generated by the disruption of medical institutions. In 2024, the cyberattack against the Children's Hospital in BrasĂlia was particularly notable, resulting in the disabling of all technology structures and the establishment of a Crisis Management Committee to investigate the incident. The Unimed cooperative system has also faced multiple cybersecurity incidents in the preceding year, including attacks against the unit established in Cuiabá, in the state of Mato Grosso, and against Unimed Vale do Taquari and Rio Pardo in the state of Rio Grande do Sul. In the case of Unimed VTRP, the attack resulted in the exposure of a series of data, necessitating a realignment of information protection procedures with the relevant authorities. This context underscores the persistent targeting of healthcare cooperatives and the operational vulnerabilities that continue to challenge the sector.
Sources
Sources available to members: 1 source.