Full Report
The Termite ransomware gang has claimed responsibility for breaching and stealing sensitive healthcare data belonging to Genea patients, one of Australia's largest fertility services providers. [...]
Analysis Summary
# Incident Report: Genea Ransomware Attack by Termite Gang
## Executive Summary
Australian IVF giant Genea suffered a ransomware attack attributed to the Termite ransomware gang, resulting in the confirmed exfiltration of approximately 700GB of sensitive data. The incident was disclosed by Genea on February 19th, though the exact date of the compromise is not specified. The investigation is ongoing, but preliminary analysis suggests the threat actors are using a variant of the Babuk encryptor, and the scope of the compromise includes confidential patient data.
## Incident Details
- **Discovery Date:** February 19 (Date of disclosure)
- **Incident Date:** Not explicitly stated in the provided text, but occurred prior to Feb 19.
- **Affected Organization:** Genea (Australian IVF giant)
- **Sector:** Healthcare/Fertility Services
- **Geography:** Australia
## Timeline of Events
### Initial Access
- **Date/Time:** Unknown
- **Vector:** Not explicitly detailed in the text, but initial access allowed for data theft.
- **Details:** Unknown.
### Lateral Movement
- **Details:** Unknown, but successful lateral movement likely occurred to facilitate the exfiltration of 700GB of data.
### Data Exfiltration/Impact
- **Details:** Approximately 700GB of data was stolen, allegedly including confidential data and patient files, as claimed by the Termite gang on their leak site. Genea confirmed an investigation into whether sensitive PII, such as credit card or bank details, was impacted.
### Detection & Response
- **How it was discovered:** Disclosed by Genea on February 19th. It is unclear if internal detection preceded the external disclosure.
- **Response actions taken:** An internal investigation was launched. Genea stated that specific sensitive financial data (credit card/bank details) had not yet been confirmed as impacted, but the investigation was ongoing.
## Attack Methodology
- **Initial Access:** Unknown.
- **Persistence:** Unknown.
- **Privilege Escalation:** Unknown.
- **Defense Evasion:** Unknown.
- **Credential Access:** Unknown.
- **Discovery:** Unknown.
- **Lateral Movement:** Implied by the exfiltration of 700GB of data.
- **Collection:** Gathering of roughly 700GB of confidential client/patient data.
- **Exfiltration:** Data was exfiltrated prior to the threat actors publishing proof on their dark web site.
- **Impact:** Data theft and extortion attempt using ransomware (though encryption details were not the focus in this report). The actors are using a version of the Babuk encryptor.
## Impact Assessment
- **Financial:** Not quantified, but significant costs associated with investigation, remediation, and potential regulatory fines are expected.
- **Data Breach:** Approximately 700GB of data stolen, purported to include confidential client and patient files. Confirmation is pending regarding PII like credit card or bank account numbers.
- **Operational:** Not detailed, but the nature of IVF services implies high sensitivity regarding disruption.
- **Reputational:** Significant damage due to the breach of sensitive patient health and fertility data.
## Indicators of Compromise
- **Network indicators:** None provided (URLs/IPs defanged).
- **File indicators:** Ransom note dropped: `How To Restore Your Files.txt` (Behavioral observation).
- **Behavioral indicators:** Posting of stolen data and proof screenshots on the Termite gang’s dark web leak site.
## Response Actions
- **Containment measures:** Not explicitly detailed.
- **Eradication steps:** Not explicitly detailed.
- **Recovery actions:** Investigation ongoing ("The investigation is however ongoing").
## Lessons Learned
- **Key takeaways:** The threat actor group Termite, utilizing Babuk-derived ransomware, is actively targeting global entities, including specialized sectors like fertility services. Sophisticated threat actors are leveraging dual extortion tactics (encryption and data theft).
- **What could have been done better:** The need for enhanced detection capabilities to catch unauthorized large-scale data exfiltration attempts affecting highly sensitive patient records promptly.
## Recommendations
- **Prevention measures for similar incidents:** Implement robust data loss prevention (DLP) strategies focused on identifying and blocking large-scale outbound transfers of sensitive files.
- Conduct immediate forensic review of initial access vectors exploited by the Termite group (often including RDP, VPN vulnerabilities, or phishing).
- Review and potentially mandate updated patching cycles for systems hosting sensitive patient data storage.