Ransomware actors are very likely using significant financial events, such as mergers and acquisitions, to target and leverage victim companies for ransomware infections, the FBI said in an alert this week to the private sector. According to the alert, the actors research material public and nonpublic information about the victim prior to an attack, and threaten to disclose the information publicly to cause potential investor backlash if victims do not pay a ransom quickly. The alert includes recommendations and links to resources to help prevent, protect and respond to a ransomware attack.

John Riggi, AHA senior advisor for cybersecurity and risk, said, “Although we are not aware of specific health care organizations being targeted by ransomware gangs to disrupt the value of a health care-related merger or acquisition, certainly an intentional or unintentional negative business consequence could result if a health care entity involved in a pending transaction became victim to a cyberattack. Thus, it is equally as important to protect sensitive non-public business information from hackers as it is to protect intellectual property.  

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org.  

Headline
FBI Co-deputy Director Andrew Bailey discussed a rise in cyber and physical threats impacting health care. He discussed health care as the top critical…
Headline
Health care and public health was the top sector targeted for cyberthreats in 2025, according to the FBI’s latest annual report on internet crimes. There were…
Headline
The Cybersecurity and Infrastructure Security Agency released an alert March 27 on a vulnerability in F5 BIG-IP Access Policy Manager software that is being…
Headline
The FBI released an alert March 20 warning of a technique used by cyber actors working on behalf of the Iranian government to conduct malicious cyber activity…
Headline
The Cybersecurity and Infrastructure Security Agency March 18 released an alert urging U.S. organizations to harden their endpoint management systems following…
Headline
The Health Sector Coordinating Council Cyber Working Group and Health-ISAC (Information Sharing and Analysis Center) will host a joint cybersecurity event July…