Massive Data Breach: Interlock Ransomware Exposes 1.5TB of Sensitive Patient Records from Fortune 500 Healthcare Giant DaVita


# Interlock Ransomware Gang Attacks DaVita Kidney Dialysis Firm, Leaks Patient Data

Fortune 500 healthcare provider DaVita has fallen victim to a significant ransomware attack claimed by the Interlock ransomware gang. The kidney care giant, which operates over 2,600 U.S. dialysis centers, employs 76,000 people across 12 countries, and generates annual revenue exceeding $12.8 billion, initially disclosed the attack in an SEC filing on April 12.

Interlock has now added DaVita to its dark web data leak site, claiming to possess approximately 1.5 terabytes of sensitive information—nearly 700,000 files reportedly containing patient records, user account information, insurance details, and financial data. The publication of these files suggests that ransom negotiations between the healthcare provider and the threat actors have failed.

In response to the situation, a DaVita spokesperson stated: “We are aware of the post on the dark web and are conducting a thorough review of the data involved. A full investigation regarding this incident is still underway. We will notify any affected parties and individuals as appropriate.” The company expressed disappointment regarding attacks targeting healthcare organizations and pledged to share information to help others defend against similar threats.

Patients who have received care at DaVita facilities should remain vigilant for potential phishing attempts and report suspicious communications to authorities.

Interlock, which emerged in September 2023, targets both Windows and FreeBSD systems. Though relatively new, the group has claimed responsibility for approximately twelve attacks, often alleging to have stolen terabytes of data from victim networks. Recent analysis from cybersecurity firm Sekoia indicates the group has evolved its tactics to include “ClickFix” strategies, tricking targets into self-infecting with information-stealing malware and remote access tools before deploying ransomware.

Share This Article