ANN & ROBERT H. LURIE CHILDREN'S HOSPITAL OF CHICAGO
bd_df9c4e148aeb5cba · schema v1 · pii pii-v1
Full breach record for ANN & ROBERT H. LURIE CHILDREN'S HOSPITAL OF CHICAGO →9 incidents on filePress / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.
Lurie Children's outage: Chicago hospital investigating 'cyber security matter' as internet, phone outage continues for 2nd day - ABC7 Chicago. Lurie Children's Hospital: Lurie Children's Hospital in Chicago is investigating a cyber security incident that has caused a disruption to their computer network, internet, and phone services for the second consecutive day. The hospital is working with experts and law enforcement to resolve the issue and has taken its network systems offline in response to the incident. This outage has forced the cancellation of some surgeries and elective procedures, and although emergency services were not affected, staff had to revert to manual work methods, such as using paper records. Linked ransomware group: rhysida.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jan 31, 2024
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Siterhysidabd_52921f58da05d5ad2024-02-27 · +27dVerified by operator
- Leak Siterhysidabd_2bd92d4f514d01f42024-01-31Verified by operator
Regulatory filings (8) · sorted by filing gap
- Illinois State AGbd_b1240fdab9182a2b2024-06-01 · +122dCandidate
- Maine State AGbd_022e63521ff140fb2024-06-27 · +148dVerified
- Massachusetts State AGbd_35c645939567579c2024-06-27 · +148dVerified
- HHS OCRbd_4d5dd308bec3adc42024-06-27 · +148dVerified by operator
Show 4 more filings ↓Show fewer ↑up to 176d gap
- Indiana State AGbd_8f4e71a1b5b1e03a2024-06-27 · +148dVerified
- California State AGbd_a10306c02fabcbf92024-06-27 · +148dVerified
- Vermont State AGbd_f01d8d4f32bfa4042024-06-27 · +148dVerified
- HHS OCRbd_100066233a59c55f2023-08-08 · +176dVerified
Filing propagation · 9 filings · 6 states
View merged incident ↗Pattern: first filing Aug 8 (IL), last Jun 27 (VT) — a 324-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
rhysida
According to ransomware.live, Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads. The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development. The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin. After encryption, the ransomware appends the extension '.ryshida' to encrypted files. Source: https://github.com/crocodyli/ThreatActors-TTPs