Booba Project crew adds four healthcare victims in 48 hours

A lesser-known extortion crew listed four medical organizations across the US and Canada in two days, claiming up to 103 GB of stolen data.

MedRisk Staff
By
1 Min Read

The Booba Project extortion crew added four healthcare victims to its leak site in a 48-hour burst, according to leak-site trackers. On October 1 it listed Associated Gastroenterologists of Central New York, claiming 70 GB of data. On October 2 it posted Soni Medical Centre in Canada (5.5 GB), dental device maker EdgeEndo USA (103 GB) and Raleigh Family Medicine (1 GB).

None of the claims has been verified, and the posts carried no ransom deadline or sample files. The pattern – a rapid string of small and mid-sized medical targets across two countries – fits the group’s fast-listing habit of bulk-building a portfolio on its dark-web page.

The victims span the width of the sector: a specialty practice, a device manufacturer, a Canadian clinic and a family medicine office. That mix underlines how the extortion threat is not confined to large health systems.

Small providers and device vendors are attractive precisely because they hold patient data but seldom run mature defenses. Basic controls still blunt most of these crews: phishing-resistant multifactor authentication, endpoint detection and response, offline and tested backups, prompt patching, and segmentation that keeps clinical systems out of reach of one stolen credential.

Share This Article