Cybersecurity researcher provides more details on $200K ransom pinned on Doctor Alliance

In an update to HealthExec’s story about a data breach allegedly impacting Doctor Alliance, “Dissident Doe, PhD” at DataBreaches.net reached out, citing his report that contains more details. 

According to the report from Doe—a cybersecurity reporter active since 2009, who claims a background in psychology and clinical research—the user “Kazu” does indeed intend to sell the data trove if a $200,000 ransom isn’t paid. Further, the individual is a notorious cybercriminal who has worked with other units, but now works on his own. Doe was able to confirm this after seeking direct comment:

“Although ‘Kazu’ is a relatively new username on the forum, the individual is not new to hacking and ransom incidents,” Doe wrote. “In the online chat, Kazu informed DataBreaches that he had worked with a number of other individuals and groups over time, but had more recently gone out on his own. He provided DataBreaches with the moniker of one of his former associates.”

HealthExec originally reported uncertainty over who the poster on the form was, and stated that his username as “GOD.” Doe clarified that this label is a “rank/status that members can buy” on the dark web forum.

We regret the error and have corrected our story. You can find that here for context. 

Doe’s report contains more information on the incident than was present in the Cybernews report, which was the basis for HealthExec’s coverage. According to Doe, she emailed Doctor Alliance to confirm the cyberattack took place, asking if it was an “incident that involved encryption or was it one involving only exfiltration with a ransom demand.”

Doctors Alliance responded, saying it was not able to confirm that Kazu’s claim of breaching their network was legitimate, but did ask for samples to make an inquiry. As Doe noted, the samples are present in the 533 images posted by the alleged hacker. 

As previously reported, these contain medical records and other personal data linked to patients whose data could have been shared through Doctor Alliance’s platform.

Subscribe to Health Exec News

HealthExec reached out to the Dallas-based company, which works to automate billing at healthcare organizations, but did not receive a reply. 

Kazu also reportedly told DataBreaches that he accessed Doctor Alliance’s network in October, declining to elaborate on how he was able to do so. However, the hacker told Doe it was made possible by an unpatched vulnerability. He is said to have proved this with a screenshot.

It is now alleged that the legacy vulnerability has been patched.

Doe said further requests for information from Doctor Alliance did not receive a reply. However, she was able to confirm that at least one law firm is already seeking plaintiffs for a potential class action lawsuit. 

This is a developing story.

Please read DataBreaches.net’s full coverage by clicking here. 

Chad Van Alstin Health Imaging Health Exec

Chad is an award-winning writer and editor with over 15 years of experience working in media. He has a decade-long professional background in healthcare, working as a writer and in public relations.

Subscribe to Health Exec News

Subscribe to Health Exec News