Extortion gang claims responsibility for Mediclinic attack

Daniel Puchert

Journalist
Staff member
Joined
Mar 6, 2024
Messages
3,336
Reaction score
3,247
Prominent private hospital group in South Africa hacked

Cyber extortion gang Everest Group has claimed responsibility for an attack on Mediclinic, stating that they exfiltrated 4GB of data and the personal data of 1,000 employees.

Mediclinic Southern Africa operates acute care private hospitals in South Africa and Namibia. It is 50% owned by Johann Rupert’s listed investment company, Remgro.
 
Lol. Still quoting Orange when there's other local companies that have already reported on this 5 days ago.... Its almost as bad as the Multichoice ads.
 
Lol. Still quoting Orange when there's other local companies that have already reported on this 5 days ago.... Its almost as bad as the Multichoice ads.
Whoever you work for is welcome to send us as detailed an analysis about the South African cybercrime threat landscape as SensePost/Orange did without any self-promotion, and I'll gladly consider including it in future articles.

I'm pretty sure there will be another breach, leak, or hack tomorrow (and the day after, and the day after that) where giving an average reader that context will be helpful, so it'll get great airplay.
 
Statement from Mediclinic.

30 May 2025
Mediclinic’s investigation into third-party cyber incident

A third-party IT service provider to Mediclinic Group (‘Mediclinic’ or the ‘Group’ or the ‘Company’) experienced a cyber security incident earlier this year which affected Mediclinic employment-related data. Upon learning of this incident, Mediclinic engaged the third-party IT service provider, who reported that it immediately took steps to ensure the containment of the incident, including immediately isolating the affected system, resetting access credentials, and working with external specialists in an incident response investigation.

As soon as Mediclinic became aware of the incident, we took immediate action to assess and protect the integrity of the Group’s IT systems, alongside our cyber security partners. This assessment determined that the data impacted is limited to employment-related data and we have taken appropriate steps to contact those whose data we believe may have been impacted by the incident, in accordance with data protection guidelines. We are confident that no patient data has been affected and we can confirm that Mediclinic did not experience any disruption to business operations.

Since the incident, we have and continue to implement further measures to enhance security safeguards in relation to our third-party vendors.

Mediclinic reported the incident to the appropriate regulators in each of our operating markets and we continue to cooperate with the relevant authorities as needed.
 
Lol. Still quoting Orange when there's other local companies that have already reported on this 5 days ago.... Its almost as bad as the Multichoice ads.
To be fair, this week we've seen the biggest variety in tech news on MBB in a long time.

Unfortunately this isn't always good for any publisher's business model. Search engines do not like variety, they like new date stamped articles on regularly searched phrases even if the actual content is old.

MBB has done wonders in terms of SEO and one would be wise to take a page from their book.
 
All companies should start improving their systems in such a way that they don't become the next victim, come to think of it, why do some wait to be a victim until it they do something??
 
All companies should start improving their systems in such a way that they don't become the next victim, come to think of it, why do some wait to be a victim until it they do something??
Many companies outsource IT and security (SaaS and ITaaS) to third-parties, so I guess they need to start employing IT people to keep an eye on the contractors..
 
I believe we have been warned that these sort of attacks will only increase. Corporate needs to get on top of this, as they are the weakest link in data breaches.

@Jan: could you guys look at giving us an article on the most prominent groups that are involved in this sort of thing, I believe that a lot of them are in fact sponsored by one government or others. It would be nice to be a bit more aware of who groups like Everest are and whether they are affiliated to one or more governments.
 
I believe we have been warned that these sort of attacks will only increase. Corporate needs to get on top of this, as they are the weakest link in data breaches.

@Jan: could you guys look at giving us an article on the most prominent groups that are involved in this sort of thing, I believe that a lot of them are in fact sponsored by one government or others. It would be nice to be a bit more aware of who groups like Everest are and whether they are affiliated to one or more governments.
Heres some historical data of these groups I have on record from my research you might find interesting
Hacker GroupBreachesEarliest BreachLast Date
8base
1​
15/06/202315/06/2023
akira
2​
22/05/202309/12/2024
alphv
3​
26/07/202309/10/2023
apt73
1​
09/01/202509/01/2025
arcusmedia
1​
03/03/202503/03/2025
bianlian
1​
25/08/202425/08/2024
blackbasta
1​
09/04/202409/04/2024
blacksuit
1​
05/07/202405/07/2024
cactus
1​
23/06/202423/06/2024
clop
3​
23/03/202330/06/2023
darkvault
2​
13/08/202413/08/2024
datacarry
1​
26/05/202526/05/2025
deathkitty
1​
22/07/202122/07/2021
devman
6​
20/04/202523/05/2025
dragonforce
1​
29/02/202429/02/2024
everest
1​
26/05/202526/05/2025
hive
1​
13/07/202213/07/2022
hunters
1​
13/04/202413/04/2024
incransom
1​
16/05/202516/05/2025
killsec
2​
26/08/202402/11/2024
lockbit2
3​
10/09/202104/06/2022
lockbit3
18​
18/07/202211/08/2024
lynx
1​
07/03/202507/03/2025
madliberator
1​
17/07/202417/07/2024
medusa
1​
13/05/202313/05/2023
monti
1​
26/08/202426/08/2024
play
1​
07/12/202307/12/2023
qilin
1​
01/11/202401/11/2024
ransomhouse
2​
22/07/202428/12/2024
ransomhub
5​
07/05/202412/02/2025
revil
1​
29/05/202029/05/2020
rhysida
1​
26/12/202326/12/2023
royal
1​
26/05/202326/05/2023
sarcoma
3​
09/10/202422/03/2025
 
I believe we have been warned that these sort of attacks will only increase. Corporate needs to get on top of this, as they are the weakest link in data breaches.

@Jan: could you guys look at giving us an article on the most prominent groups that are involved in this sort of thing, I believe that a lot of them are in fact sponsored by one government or others. It would be nice to be a bit more aware of who groups like Everest are and whether they are affiliated to one or more governments.
You might find this infographic cool
timeline_visualization copy.png
 
A hacker only needs to get lucky once. In order to protect a service you need to be lucky every time across all the systems, people and software in the organisation.
 
All companies should start improving their systems in such a way that they don't become the next victim, come to think of it, why do some wait to be a victim until it they do something??
Saw a job post where the company is hiring specifically vibe coders. I also use AI but mostly to help with something I am missing. Most of the time AI points me in the right direction but it also makes some very basic and stupid mistakes.

AI is great to understand the problem better and filter out the noise from the overload of results, but to code with it exclusively/mostly? Maybe for frontend? But the post included backend coding...

At the same time it was one of the few companies boasting about being POPI compliant but the regulator says different. This is why we will see more data breaches, its so easy for software/SaaS companies to be dishonest, how can users know better?
 
Saw a job post where the company is hiring specifically vibe coders. I also use AI but mostly to help with something I am missing. Most of the time AI points me in the right direction but it also makes some very basic and stupid mistakes.

AI is great to understand the problem better and filter out the noise from the overload of results, but to code with it exclusively/mostly? Maybe for frontend? But the post included backend coding...

At the same time it was one of the few companies boasting about being POPI compliant but the regulator says different. This is why we will see more data breaches, its so easy for software/SaaS companies to be dishonest, how can users know better?

Just this week Gitlab Duo missed the brief and put a tiny NOT statement into some code which slipped past for literally being only three letters and it ****ed us properly.

Ironically I asked Gemini for an F1 prediction before qualifying today just for fun and it said Perez would be 5th.

If you don’t follow F1…Perez isn’t taking part in 2025.

It really is a danger. Sure it can save you hours of minutia but like any junior you need to check its work and actually understand it before you implement it anywhere.
 
Heres some historical data of these groups I have on record from my research you might find interesting
Hacker GroupBreachesEarliest BreachLast Date
8base
1​
15/06/202315/06/2023
akira
2​
22/05/202309/12/2024
alphv
3​
26/07/202309/10/2023
apt73
1​
09/01/202509/01/2025
arcusmedia
1​
03/03/202503/03/2025
bianlian
1​
25/08/202425/08/2024
blackbasta
1​
09/04/202409/04/2024
blacksuit
1​
05/07/202405/07/2024
cactus
1​
23/06/202423/06/2024
clop
3​
23/03/202330/06/2023
darkvault
2​
13/08/202413/08/2024
datacarry
1​
26/05/202526/05/2025
deathkitty
1​
22/07/202122/07/2021
devman
6​
20/04/202523/05/2025
dragonforce
1​
29/02/202429/02/2024
everest
1​
26/05/202526/05/2025
hive
1​
13/07/202213/07/2022
hunters
1​
13/04/202413/04/2024
incransom
1​
16/05/202516/05/2025
killsec
2​
26/08/202402/11/2024
lockbit2
3​
10/09/202104/06/2022
lockbit3
18​
18/07/202211/08/2024
lynx
1​
07/03/202507/03/2025
madliberator
1​
17/07/202417/07/2024
medusa
1​
13/05/202313/05/2023
monti
1​
26/08/202426/08/2024
play
1​
07/12/202307/12/2023
qilin
1​
01/11/202401/11/2024
ransomhouse
2​
22/07/202428/12/2024
ransomhub
5​
07/05/202412/02/2025
revil
1​
29/05/202029/05/2020
rhysida
1​
26/12/202326/12/2023
royal
1​
26/05/202326/05/2023
sarcoma
3​
09/10/202422/03/2025
Thank you very much, this is greatly appreciated
 
  • Like
Reactions: Jan
Top
Sign up to the MyBroadband newsletter
X