Ransomware gang continues to publish data stolen from Ontario hospitals

November 6, 2023 The Daxin Team ransomware group has released its third tranche of data stolen from southwestern Ontario hospitals that share an IT services provider because it can’t get a penny from the institutions.

According to Canadian-based Emsisoft threat researcher Brett Callow, this third installment of data was released Sunday. The gang promises to release databases full of information soon.

The institutions in the group — Bluewater Health of Sarnia, Chatham Kent Health Alliance, Erie Shores HealthCare of Leamington, Hôtel-Dieu Grace Healthcare and Windsor Regional Hospital, along with shared service provider TransForm Shared Service Organization — were hit by a cyber attack late last month that forced the curtailment of some healthcare services.

The websites of the hospitals continue to post an alert notice that their IT systems are still suffering from the attack. It says they are working “around the clock to restore systems.”

According to DataBreaches.net, this latest leak has a great deal of sensitive patient information and IT-related information.

The news site also says it spoke to someone from the group who said it has been considering different strategies for dealing with victims who do not pay, including possibly selling some of the stolen data rather than leaking it.

In an earlier story, the spokesman for the attackers said, “the networks were completely transparent – we could go anywhere.”  When DataBreaches asked if that was because of password re-use or failure to segment, or some other reason, Daixin answered, “Maybe they had some kind of segmentation, but the fact that even the wifi in the hospitals disappeared after we attacked can speak to its level. The passwords for some administrator accounts across all hospital domains were the same.”

When asked how many files had been encrypted the person replied, “I’m assuming we’re talking about thousands of hosts.”

The post Ransomware gang continues to publish data stolen from Ontario hospitals first appeared on IT World Canada.

Top Stories

Related Articles

February 5, 2026 A security researcher at Koi named Oren Yomtov has uncovered a widespread malware operation embedded inside an more...

February 4, 2026 More than three million Fortinet devices have been exposed to a critical authentication-bypass vulnerability that is being more...

February 4, 2026 A now-patched security flaw in Docker’s built-in AI assistant exposed users to the risk of remote code more...

January 28, 2026 A suspected credit card skimming attack on the Canada Computers online store may have quietly exposed customer more...

Picture of Howard Solomon

Howard Solomon

Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.
Picture of Howard Solomon

Howard Solomon

Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn