New VoidLock RaaS Targets Healthcare Sector

Double-extortion group claims 47 victims in first month. Average ransom demand reaches $4.2M.

A new ransomware-as-a-service (RaaS) operation called VoidLock has emerged, specifically targeting the healthcare sector. In its first month of operation, the group has claimed 47 victims across hospitals, clinics, and healthcare IT providers.

VoidLock operates on a double-extortion model, encrypting victim data and exfiltrating sensitive patient information for leverage. The average ransom demand is $4.2 million, with some demands exceeding $10 million for large hospital networks.

The FBI and CISA recommend healthcare organizations implement network segmentation, maintain offline backups, and deploy endpoint detection and response (EDR) solutions to mitigate the risk.

Source: Dragos Threat Intelligence