{"id":48919,"date":"2022-10-18T14:14:41","date_gmt":"2022-10-18T14:14:41","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/33945\/Ransomware-Attack-Impacted-Some-CommonSpirit-Sites.html"},"modified":"2022-10-18T14:14:41","modified_gmt":"2022-10-18T14:14:41","slug":"ransomware-attack-impacted-some-commonspirit-sites","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/","title":{"rendered":"Ransomware Attack Impacted Some CommonSpirit Sites"},"content":{"rendered":"<div>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/cms.scmagazine.com\/wp-content\/uploads\/2022\/10\/101722_emergency_entrance-1024x614.jpg\" alt class=\"wp-image-455081\"><figcaption>CommonSpirit Health confirmed that some of its sites in 21 states were impacted by a ransomware attack, but few other details have been released weeks later. (Air Force)<\/figcaption><\/figure>\n<\/div>\n<p>Now into its third week of care disruptions, a <a href=\"https:\/\/www.commonspirit.org\/news-and-perspectives\/news\/statement-it-security-issue\" target=\"_blank\" rel=\"noreferrer noopener\">new update from CommonSpirit<\/a> Health confirms that only a portion of its 700 care sites and 142 hospitals in 21 states have been impacted by the ransomware attack and subsequent IT and network outages.<\/p>\n<p>\u201cThere is no impact to clinic, patient care and associated systems at Dignity Health, Virginia Mason Medical Center, TriHealth or Centura Health facilities,\u201d officials said in a statement. \u201cPatients continue to receive the highest quality of care, and we are providing relevant updates on the ongoing situation to our patients, employees, and caregivers. Patient care remains our utmost priority.\u201d<\/p>\n<p>Patient safety has been \u201ccentral to our decision-making,\u201d CommonSpirit officials stated. The care team is continuing to \u201ccarry out our mission in a manner that is safe and effective to those we serve.\u201d<\/p>\n<p>Dignity Health is made up of 12 hospital or care facilities and 125 provider offices; TriHealth has 400 care sites and 39 hospitals; and Centura Health has 19 hospitals and what appears to be 488 provider offices. As such, it appears the bulk of the impact is concentrated in CHI Health facilities and Virginia Mason Franciscan Health, outside of VMMC.<\/p>\n<p>It appears that the impact is much smaller than sensationalized reports note. However, as <a href=\"https:\/\/www.scmagazine.com\/analysis\/ransomware\/commonspirit-cyberattack-renews-patient-safety-concerns-amid-outages-care-delays\" target=\"_blank\" rel=\"noreferrer noopener\">Carter Groome, First Health Advisory<\/a> CEO recently explained: \u201cPatients suffer when their care is delayed, disrupted, and otherwise diverted,\u201d with \u201cindisputable\u201d consequences.<\/p>\n<p>Even if just one hospital was hit, \u201ca breach to one organization is a breach to our entire critical infrastructure of healthcare.\u201d<\/p>\n<p>To better understand what may be going on behind the scenes and possible reasons for communication gaps, SC Media tuned in to a Critical Insights webcast and spoke with Jon Moore, Clearwater\u2019s chief risk officer and senior vice president of services and customer success.<\/p>\n<p>\u201cYou want to be really careful throwing stones in glass houses,\u201d Moore stressed. It\u2019s truly the conundrum of the Health Insurance Portability and Accountability Act Security rule, where providers are victims of an attack launched by a nation-state or criminal actor, \u201cwhich is not a trivial foe to be attacked by,\u201d and then \u201cwe end up blaming the victim,&#8221; he continued.<\/p>\n<p>As a bystander, it\u2019s easy to watch the attack unfurl and immediately cast blame, but nothing is necessarily clear yet and all finger-pointing stems from conjecture. Until the facts are revealed about the incident, it will be impossible to know if they took HIPAA-required measures, or were negligent.<\/p>\n<h2>Scant details amid attack fallout, but what does HIPAA require?<\/h2>\n<p>As <a href=\"https:\/\/www.scmagazine.com\/analysis\/ransomware\/commonspirit-cyberattack-spurs-it-outages-at-chi-memorial-hospitals-across-us\" target=\"_blank\" rel=\"noreferrer noopener\">previously reported by SC Media<\/a>, the Department of Health and Human Services confirmed a ransomware attack struck the network of hospitals on or around Oct. 3, prompting the response team to take the electronic health record and other systems offline to prevent the spread, at CommonHealth subsidiaries and hospitals across the country.&nbsp;<\/p>\n<p>Until its latest notice, CommonSpirit had remained tight-lipped about the scope of the incident, which has caused outcry among nurses, patients, and even one security leader at an impacted hospital \u2014 all noting how the massive health system should be communicating its progress.<\/p>\n<p>But, if CommonSpirit is in direct communication with HHS leaders and has been working with law enforcement on its investigation, have they done their due diligence?<\/p>\n<p>\u201cThey&#8217;re not being completely forthcoming yet, but they don&#8217;t have to,\u201d Fred Langston, Critical Insights\u2019 founder and chief product officer, recently said during a webcast. But there\u2019s likely a lot of negotiating going on at the moment, as the FBI and the insurance company are involved, in partnership with the team working to bring the systems back online to reduce the impact on hospitals that rely on CommonSpirit for their EHR.<\/p>\n<p>Communication might also be stymied by the number of parties involved, as well as coordination with law enforcement, Moore explained. And it\u2019s likely CommonSpirit\u2019s cyber liability insurance carrier is also involved with its legal team. \u201cThere&#8217;s a lot of other people weighing in on what information is being communicated, and to whom.\u201d&nbsp;<\/p>\n<p>CommonSpirit is in \u201ca bit of a challenging situation,\u201d he added. The incident response group is probably being briefed regularly on the status, with a lot of information, including a lot of unknowns. The team is \u201cprobably being very careful to make sure what they say is factual.\u201d<\/p>\n<p>As Moore put it, if you&#8217;ve ever been in some of these crisis situations in organizations, some people take the approach of being \u201cas open, truthful, and honest, as we can.\u201d Other individuals may align with the ideology that sharing each step may create \u201cmore ammunition for people to poke at us.\u201d<\/p>\n<p>\u201cIt becomes more of marketing, political\/legal conversation than anything else,\u201d he added. The publicized information is likely sensitive to any possible class-action lawsuits that may come from the incident, as well as possible reporting obligations and any care disruptions that could impact their ability to safely provide care.<\/p>\n<p>HIPAA outlines precise reporting guidelines as they relate to a security incident and whether there\u2019s been a breach of protected health information. But that is not needed until 60 days later, and that timer does not start until the breach has been discovered. As the Department of Health and Human Services is in direct contact with CommonSpirit, they appear to be following regulations.<\/p>\n<h2>The nature of cyberattack recovery processes<\/h2>\n<p>As Moore notes, typically in these kinds of outages there\u2019s a lot going on behind the scenes that can range from \u201cchaos, to the execution of a well-laid plan.\u201d It\u2019s currently unclear where CommonSpirit is on that spectrum. Given its size, \u201cwe can speculate they&#8217;re probably not in chaos, but probably not as efficient as they could be in the execution of the incident response plans they may or may not have in place.\u201d<\/p>\n<p>CommonSpirit is likely in the middle of a technical track, working to understand the nature of the attack, the variant used, the details of the attack itself, and its efforts to contain it, before moving to eradication. Moore explains they\u2019re likely in the containment mode, actively shutting off systems to prevent the spread of the ransomware. Some systems may be down because of a direct infection, while others were likely turned off to prevent the spread of the infection.<\/p>\n<p>Once they move past that stage, they\u2019ll move into the \u201ceradication mode,\u201d which will depend, to a certain extent, on whether they&#8217;ve identified the variant of ransomware used by looking for those indicators within their systems and try to remove those, Moore explained.<\/p>\n<p>However, \u201cthey need to be careful doing that because if they&#8217;re on that parallel track, potentially negotiating with the attackers themselves, and begin eradicating things, and that can, to a certain extent, remove their ability to pay the ransom, because you&#8217;ve taken down the pieces that would facilitate that,\u201d he added.<\/p>\n<p>Hopefully, the provider previously conducted a business impact analysis that would have created \u201ctier systems\u201d that dictate the order of technical recovery based on the impact to necessary business processes, said Moore. As such, they may be steadily working through those tiers to get mission critical systems back online as soon as possible.<\/p>\n<p>CommonSpirit could also be dealing with impacts to its backup systems or files, which could impact recovery, as well. But what\u2019s clear is that they\u2019re still working through these processes. The EHRs were not accessible, so while the responsibility may not fall on one particular entity\u2019s shoulders, \u201cas a hospital, if you still can&#8217;t access your EHR, that&#8217;s catastrophic,\u201d Langston noted.<\/p>\n<p>\u201cBecause right now, if you go to a hospital, and you had a chemo session scheduled, they&#8217;re having to reschedule,\u201d said Michael Hamilton, Critical Insights CISO. \u201cThere&#8217;s no record now that says, here are the antibiotics I&#8217;m allergic to.\u201d<\/p>\n<h2>A call to action for health system leadership<\/h2>\n<p>CommonSpirit is an \u201cinteresting juxtaposition of things,\u201d the day before the cyberattack and IT outage was reported, the provider \u201cposted a billion dollar operating loss, which is common in the health sector,\u201d explained Hamilton.<\/p>\n<p>\u201cThe health sector is on the ropes between its revenue down and margins down, and having to pay traveling nurses instead of staff nurses \u2014 hospitals are having a real hard time,\u201d he continued. They posted an operating loss, and a day later, issued a $1.5 million bond. \u201cI don&#8217;t know if the event that&#8217;s going on right now is going to impede their ability to raise funds because they certainly need to raise funds.\u201d<\/p>\n<p>However, CommonSpirit is a parent company of hundreds of care sites and hospitals, as well as a provider of a lot of shared services like EHRs, which means the full impact of the event could be far greater than expected.<\/p>\n<p>What\u2019s clear is that only a portion of CommonSpirit subsidiaries have been impacted, which indicates that only some care sites are sharing the IT and systems impacted by the ransomware attack. It could be that they were able to segment off their systems. As Moore noted, it\u2019s the complexity of these disparate systems that may have reduced the impact, but it simultaneously increases the CommonSpirit footprint and likelihood of an unpatched vulnerability.<\/p>\n<p>As theories and patient safety concerns, continue to be shared, \u201cthe bottom line is, you&#8217;re out of your EHR,\u201d said Langston. \u201cAffixing blame is ultimately down the road when the law dogs get involved. But this is really about, does your chief medical officer understand what to do if there&#8217;s a breach that isn&#8217;t even yours, preventing you from giving care?\u201d<\/p>\n<p>\u201cMoving to pencil and paper is viable, but you cannot handle the volume of clients, especially if we&#8217;re in the middle of a pandemic, we&#8217;re heading into the the flu season, and kids are back in school\u2026all these things are gonna start impacting the volume of patients they can see. And if you slow down and pencil on paper, you&#8217;re probably going to be diverting patients or canceling elective surgeries,\u201d he added.<\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/33945\/Ransomware-Attack-Impacted-Some-CommonSpirit-Sites.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":48920,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[6316],"class_list":["post-48919","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinemalwarefraudcryptography"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Ransomware Attack Impacted Some CommonSpirit Sites 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Ransomware Attack Impacted Some CommonSpirit Sites 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-10-18T14:14:41+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cms.scmagazine.com\/wp-content\/uploads\/2022\/10\/101722_emergency_entrance-1024x614.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-attack-impacted-some-commonspirit-sites\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-attack-impacted-some-commonspirit-sites\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Ransomware Attack Impacted Some CommonSpirit Sites\",\"datePublished\":\"2022-10-18T14:14:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-attack-impacted-some-commonspirit-sites\\\/\"},\"wordCount\":1703,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-attack-impacted-some-commonspirit-sites\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/10\\\/ransomware-attack-impacted-some-commonspirit-sites.jpg\",\"keywords\":[\"headline,malware,fraud,cryptography\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-attack-impacted-some-commonspirit-sites\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-attack-impacted-some-commonspirit-sites\\\/\",\"name\":\"Ransomware Attack Impacted Some CommonSpirit Sites 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-attack-impacted-some-commonspirit-sites\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-attack-impacted-some-commonspirit-sites\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/10\\\/ransomware-attack-impacted-some-commonspirit-sites.jpg\",\"datePublished\":\"2022-10-18T14:14:41+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-attack-impacted-some-commonspirit-sites\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-attack-impacted-some-commonspirit-sites\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-attack-impacted-some-commonspirit-sites\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/10\\\/ransomware-attack-impacted-some-commonspirit-sites.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/10\\\/ransomware-attack-impacted-some-commonspirit-sites.jpg\",\"width\":1024,\"height\":614},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-attack-impacted-some-commonspirit-sites\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,malware,fraud,cryptography\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinemalwarefraudcryptography\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Ransomware Attack Impacted Some CommonSpirit Sites\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Ransomware Attack Impacted Some CommonSpirit Sites 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/","og_locale":"en_US","og_type":"article","og_title":"Ransomware Attack Impacted Some CommonSpirit Sites 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-10-18T14:14:41+00:00","og_image":[{"url":"https:\/\/cms.scmagazine.com\/wp-content\/uploads\/2022\/10\/101722_emergency_entrance-1024x614.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Ransomware Attack Impacted Some CommonSpirit Sites","datePublished":"2022-10-18T14:14:41+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/"},"wordCount":1703,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/10\/ransomware-attack-impacted-some-commonspirit-sites.jpg","keywords":["headline,malware,fraud,cryptography"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/","url":"https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/","name":"Ransomware Attack Impacted Some CommonSpirit Sites 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/10\/ransomware-attack-impacted-some-commonspirit-sites.jpg","datePublished":"2022-10-18T14:14:41+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/10\/ransomware-attack-impacted-some-commonspirit-sites.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/10\/ransomware-attack-impacted-some-commonspirit-sites.jpg","width":1024,"height":614},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/ransomware-attack-impacted-some-commonspirit-sites\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,malware,fraud,cryptography","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinemalwarefraudcryptography\/"},{"@type":"ListItem","position":3,"name":"Ransomware Attack Impacted Some CommonSpirit Sites"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/48919","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=48919"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/48919\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/48920"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=48919"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=48919"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=48919"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}