Duty Analyst: Moises Salas Lopez

Blog

Insights & Blog

Investigación, notas de ingeniería de detección y lecciones aprendidas en respuesta a incidentes.

Latest

122 articles published.

Kettering Health crippled by ransomware: 14 hospitals on emergency reroute

On May 20, 2025, Kettering Health, a major healthcare network based in Ohio, experienced a ransomware attack that severely disrupted its operations. As a result, all 14 hospitals in the system were placed on emergency reroute. This meant ambulances were redirected, and staff had to switch to manual processes because digital systems—including electronic health records, internal messaging, and coordination platforms—became unavailable.

Donation-Based Ransomware Groups

In the constantly evolving world of ransomware, a new and unusual variation has emerged. Rather than demanding cryptocurrency payments, certain threat actors are now instructing victims to make donations to charity in exchange for decryption keys or promises not to publish stolen data. These so-calleddonation-model ransomware groupspresent themselves as ideologically driven, often citing anti-corporate motives or positioning their activity as a form of digital protest.