McLaren hospitals disruption linked to INC ransomware attack

Share:

​On Tuesday, IT and phone systems at McLaren Health Care hospitals were disrupted following an attack linked to the INC Ransom ransomware operation.

McLaren is a non-profit healthcare system with annual revenues of over $6.5 billion, which operates a network of 13 hospitals across Michigan supported by a team of 640 physicians. It also has over 28,000 employees and works with 113,000 network providers throughout Michigan, Indiana, and Ohio.

“While McLaren Health Care continues to investigate a disruption to our information technology system, we want to ensure our teams are as prepared as possible to care for patients when they arrive,” a statement on the health system’s website reads.

“Patients with scheduled appointments should plan to attend those appointments unless they are contacted by a member of our care team.

McLaren hinted the hospitals had lost access to patient information databases when advising patients to bring detailed information about their current medications to appointments, including physician orders and printed results of recent lab tests. The health system also said it may have to reschedule some appointments and non-emergent or elective procedures “out of an abundance of caution.”

“We understand this situation may be frustrating to our patients – and to our team members – and we deeply and sincerely apologize for any inconvenience this may cause,” McLaren added. “We kindly ask for your patience while our caregivers and support teams work as diligently as ever to provide our communities the care they need and deserve.”

Even though McLaren has yet to disclose the nature of the incident, employees at McLaren Bay Region Hospital in Bay City have shared a ransom note warning that the hospital’s systems have been encrypted and stolen data will be published on INC RANSOM ransomware gang’s leak site if a ransom is not paid.

​INC Ransom is a ransomware-as-a-service (RaaS) operation that surfaced in July 2023 and has since targeted organizations in both the public and private sectors.

The list of victims includes education, healthcare, government, and industrial entities like Yamaha Motor Philippines, the U.S. division of Xerox Business Solutions (XBS), and Scotland’s National Health Service (NHS).

In May, a threat actor known as “salfetka” claimed to be selling source code of INC Ransom’s Windows and Linux/ESXi encrypter versions for $300,000 on the Exploit and XSS hacking forums.

Two months later, in July, malware analysts stated that the source code might have been purchased by a newly emerged ransomware group called Lynx ransomware. However, this could also be a rebranding effort, potentially allowing INC RANSOM to continue operations with less scrutiny from law enforcement.

BleepingComputer did an analysis of strings between the new Lynx ransomware encryptors and recent INC encryptors, and other than small changes, can confirm they are mostly the same.

​In November 2023, McLaren notified almost 2.2 million people of a data breach that exposed their personal and health information between late July and August 2023.

Compromised data included names, Social Security numbers, health insurance and physician information, as well as Medicare/Medicaid, prescription/medication, and diagnostic results and treatment information.

The ALPHV/BlackCat ransomware group claimed the July 2023 attack behind the data breach on October 4.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:18 pm, Jun 21, 2025
weather icon 25°C
L: 23° | H: 26°
broken clouds
Humidity: 54 %
Pressure: 1013 mb
Wind: 12 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 59%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
23° | 26°°C 0.25 mm 25% 16 mph 64 % 1014 mb 0 mm/h
Mon Jun 23 10:00 pm
weather icon
15° | 23°°C 0.2 mm 20% 15 mph 80 % 1016 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
13° | 25°°C 0 mm 0% 14 mph 80 % 1016 mb 0 mm/h
Wed Jun 25 10:00 pm
weather icon
16° | 28°°C 0.21 mm 21% 10 mph 85 % 1014 mb 0 mm/h
Thu Jun 26 10:00 pm
weather icon
16° | 20°°C 1 mm 100% 12 mph 95 % 1015 mb 0 mm/h
Tomorrow 1:00 am
weather icon
21° | 24°°C 0.2 mm 20% 8 mph 55 % 1014 mb 0 mm/h
Tomorrow 4:00 am
weather icon
17° | 20°°C 0.25 mm 25% 9 mph 64 % 1013 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 10 mph 64 % 1014 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 12 mph 49 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 14 mph 34 % 1013 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
24° | 24°°C 0 mm 0% 16 mph 41 % 1012 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
23° | 23°°C 0 mm 0% 14 mph 51 % 1012 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
19° | 19°°C 0 mm 0% 10 mph 59 % 1013 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€88,261.57
-1.57%
Ethereum(ETH)
€1,989.38
-4.90%
Tether(USDT)
€0.87
0.00%
XRP(XRP)
€1.77
-3.58%
Solana(SOL)
€115.91
-4.39%
USDC(USDC)
€0.87
-0.01%
Dogecoin(DOGE)
€0.132983
-5.41%
Shiba Inu(SHIB)
€0.000010
-4.37%
Pepe(PEPE)
€0.000008
-6.31%
Peanut the Squirrel(PNUT)
€0.218233
13.10%
Scroll to Top