{"id":49593,"date":"2022-12-06T15:58:36","date_gmt":"2022-12-06T15:58:36","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/34113\/CommonSpirit-Confirms-Network-Accessed-A-Week-Before-Ransomware-Attack.html"},"modified":"2022-12-06T15:58:36","modified_gmt":"2022-12-06T15:58:36","slug":"commonspirit-confirms-network-accessed-a-week-before-ransomware-attack","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/","title":{"rendered":"CommonSpirit Confirms Network Accessed A Week Before Ransomware Attack"},"content":{"rendered":"<div>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/cms.scmagazine.com\/wp-content\/uploads\/2022\/12\/120522_pharmacy-1024x614.jpg\" alt class=\"wp-image-463818\"><figcaption>CommonSpirit Health confirmed that threat actors accessed patient data before a ransomware attack took down multiple hospitals nationwide. (Air Force)<\/figcaption><\/figure>\n<\/div>\n<p>CommonSpirit Health issued an update on the ransomware attack that brought down multiple hospitals across the country for more than a month, confirming the threat actors first gained network access weeks before the attack and patient data was, indeed, accessed.<\/p>\n<p>As<a href=\"https:\/\/www.scmagazine.com\/analysis\/ransomware\/commonspirit-cyberattack-spurs-it-outages-at-chi-memorial-hospitals-across-us\" target=\"_blank\" rel=\"noreferrer noopener\"> previously reported<\/a>, the attackers first struck CommonSpirit on Oct. 2 and spurred network IT outages at various care sites operated by the country\u2019s second-largest nonprofit hospital chain. While reports suspected all 142 hospitals and 700 care sites were impacted,<a href=\"https:\/\/www.scmagazine.com\/analysis\/ransomware\/ransomware-attack-impacted-some-commonspirit-sites-but-few-details-released\" target=\"_blank\" rel=\"noreferrer noopener\"> the attack did not affect <\/a>Dignity Health, TriHealth, Virginia Mason Medical Center, or Centura Health.<\/p>\n<p>The impact was much smaller than originally projected, as was the data impact.<\/p>\n<p>The total number of patients has yet to be shared on the Department of Health and Human Services breach reporting tool, but the breach notice shows only health information from Franciscan Medical Group and\/or Franciscan Health in Washington was accessed \u2014 a small fraction when considering the scope of CommonSpirit\u2019s reach and overall hospital outages.<\/p>\n<p>The notice also shows that hospital networks were taken offline proactively to contain the spread and secure the network. With support from an external cybersecurity specialist, the investigation found that the attackers first gained access on Sept. 16, using the dwell time to access files of certain current and former patients, as well as some family members.<\/p>\n<p>The investigation into the data impact is ongoing, but it appears seven hospitals and provider clinics collectively known as Virginia Mason Franciscan Health, an affiliated entity of CommonSpirit. So far, it appears the compromised data includes names, contact details, dates of birth, and a unique ID used internally by the entity.<\/p>\n<p>Law enforcement is continuing to investigate the cyberattack, as well, and CommonSpirit returned the affected systems to the network with additional security and monitoring tools.<\/p>\n<h2>Data of 2.2 million patients stolen in pediatric EMR hack<\/h2>\n<p>Connexin Software, an electronic medical records and practice management software vendor for pediatric physician practice groups, <a href=\"https:\/\/www.officepracticum.com\/substitute-notice\/\" target=\"_blank\" rel=\"noreferrer noopener\">recently notified 2.22 million<\/a> patients that their data was accessed and stolen by a third-party threat actor during a hack of an internal computer network.<\/p>\n<p>According to the notice, approximately 119 provider offices were impacted by the hack. With its report to HHS, the incident is now the third-largest healthcare data breach reported this year.<\/p>\n<p>A \u201cdata anomaly\u201d was detected on Connexin\u2019s network on Aug. 26, which prompted an investigation. Two weeks later, they discovered an unauthorized party \u201caccessed an offline set of patient data used for data conversion and troubleshooting,\u201d and removed it from the network.&nbsp;&nbsp;<\/p>\n<p>An analysis found the stolen data varied by patient and could include names, guarantor names, parent or guardian names, contact details, dates of birth, Social Security numbers, highly specific health insurance information, treatments, procedures, diagnoses, prescriptions, provider names, medical record numbers, and billing and\/or claims data,<\/p>\n<p>Connexin officials stressed that the live EMR system wasn\u2019t hacked during the incident, nor were any systems, EMRs, or databases belonging to physician practice groups. The vendor has since reset all enterprise passwords and moved all patient data into a more secure environment.<\/p>\n<p>Law environment is continuing to investigate the incident, as Connexin works to enhance its security and monitoring capabilities to prevent a recurrence.<\/p>\n<h2>DHCHD informs 70,000 patients of systems hack, data theft<\/h2>\n<p>A systems hack against <a href=\"https:\/\/dhchd.org\/notice-of-data-incident\/\" target=\"_blank\" rel=\"noreferrer noopener\">Dallam Hartley Counties<\/a> Hospital District (DHCHD) in Texas on Sept. 28, led to the theft of protected health information tied to nearly 70,000 patients.<\/p>\n<p>The notice suggests the \u201ccybersecurity incident\u201d was a ransomware attack or another malware variant, as DHCHD \u201ctook measures to contain the incident\u201d and contacted law enforcement. Only some of DHCHD\u2019s systems were impacted.<\/p>\n<p>An investigation supported by a third-party forensics firm found that the attacker first gained access to the network the day before it was detected and used the access to acquire a subset of files containing patient data, like names, SSNs, health insurance information, demographic details, and limited medical information.&nbsp;<\/p>\n<p>The EMR application was not accessed during the incident. All impacted patients are being offered complimentary credit monitoring and identity theft protection services. DHCHD is currently working to bolster its security.<\/p>\n<h2>85,000 Mena Regional Health patients informed of data theft<\/h2>\n<p>The data of 84,814 patients tied to <a href=\"https:\/\/menaregional.com\/notice-of-data-security-incident\/\" target=\"_blank\" rel=\"noreferrer noopener\">Mena Regional Health System<\/a> in Arkansas were recently notified that their data was exfiltrated more than a year ago on Oct. 30, 2021.<\/p>\n<p>The notice uses careful language, omitting when the incident was first discovered. Instead, MRHS explained that the investigation revealed on \u201cNov. 8, 2022 that one or more of the files removed by the unauthorized party\u201d contained patient information. It\u2019s an important distinction, as<a href=\"https:\/\/www.scmagazine.com\/analysis\/security-awareness\/hipaa-requires-timely-response-for-security-incidents-says-alert-to-health-sector\" target=\"_blank\" rel=\"noreferrer noopener\"> HHS recently reminded providers<\/a> of the HIPAA-required 60-day timeframe for reporting.<\/p>\n<p>What\u2019s clear is that the incident was caused by an actor removing some patient files from the network. The data included patient names, SSNs, dates of birth, driver\u2019s licenses, government IDs, financial account details, medical record or patient account numbers, diagnoses, treatments, provider names, lab results, prescriptions, and health insurance information.<\/p>\n<p>The stolen and\/or accessed data varied by patient, and all patients whose SSNs were compromised will receive credit monitoring services.<\/p>\n<h2>CCA Health California reports monthslong hack, data exfiltration<\/h2>\n<p>Approximately 15,000 CCA Health California current and former health plan members were recently notified that their data was exfiltrated from the insurer\u2019s network during a monthslong hack that began as far back as May 4.<\/p>\n<p>The incident was detected on Sept. 16, which&nbsp; \u201cdisrupted the operations\u201d of a portion of the IT systems of what was formerly known as Vitality Health Plan of California, now owned by CCA Health California.<\/p>\n<p>Once the systems were secured, an investigation was launched with outsider support and law enforcement was notified. They found that a threat actor used the lengthy downtime to remove certain files, some of which contained patient data. Only CCA Health California&#8217;s systems were accessed during the incident.<\/p>\n<p>The stolen or accessed data involved member information, such as names, SSNs, dates of birth, contact details, demographic information, passport numbers, diagnoses, treatments, prescriptions, medical record numbers, lab test results, provider names, dates of service, and\/or health insurance and plan member information.<\/p>\n<p>CCA Health California has since improved its existing security safeguards, monitoring capabilities, and other technical measures.<\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/34113\/CommonSpirit-Confirms-Network-Accessed-A-Week-Before-Ransomware-Attack.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":49594,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[277],"tags":[1647],"class_list":["post-49593","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-blogs","tag-headlinehackerprivacydata-loss"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CommonSpirit Confirms Network Accessed A Week Before Ransomware Attack 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CommonSpirit Confirms Network Accessed A Week Before Ransomware Attack 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-12-06T15:58:36+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cms.scmagazine.com\/wp-content\/uploads\/2022\/12\/120522_pharmacy-1024x614.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"CommonSpirit Confirms Network Accessed A Week Before Ransomware Attack\",\"datePublished\":\"2022-12-06T15:58:36+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\\\/\"},\"wordCount\":1056,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack.jpg\",\"keywords\":[\"headline,hacker,privacy,data loss\"],\"articleSection\":[\"CyberSecurity Blogs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\\\/\",\"name\":\"CommonSpirit Confirms Network Accessed A Week Before Ransomware Attack 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack.jpg\",\"datePublished\":\"2022-12-06T15:58:36+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack.jpg\",\"width\":1024,\"height\":614},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,privacy,data loss\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackerprivacydata-loss\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"CommonSpirit Confirms Network Accessed A Week Before Ransomware Attack\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CommonSpirit Confirms Network Accessed A Week Before Ransomware Attack 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/","og_locale":"en_US","og_type":"article","og_title":"CommonSpirit Confirms Network Accessed A Week Before Ransomware Attack 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-12-06T15:58:36+00:00","og_image":[{"url":"https:\/\/cms.scmagazine.com\/wp-content\/uploads\/2022\/12\/120522_pharmacy-1024x614.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"CommonSpirit Confirms Network Accessed A Week Before Ransomware Attack","datePublished":"2022-12-06T15:58:36+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/"},"wordCount":1056,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/12\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack.jpg","keywords":["headline,hacker,privacy,data loss"],"articleSection":["CyberSecurity Blogs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/","url":"https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/","name":"CommonSpirit Confirms Network Accessed A Week Before Ransomware Attack 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/12\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack.jpg","datePublished":"2022-12-06T15:58:36+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/12\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/12\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack.jpg","width":1024,"height":614},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/commonspirit-confirms-network-accessed-a-week-before-ransomware-attack\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,privacy,data loss","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackerprivacydata-loss\/"},{"@type":"ListItem","position":3,"name":"CommonSpirit Confirms Network Accessed A Week Before Ransomware Attack"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/49593","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=49593"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/49593\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/49594"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=49593"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=49593"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=49593"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}