
HHS cybersecurity center notes “very aggressive” threat by Hive hacking group
Ransomware groups targeting health organizations, physicians’ offices.
The U.S. Department of Health and Human Services (HHS) is warning health care providers about an aggressive 
The HHS 
“Hive is an exceptionally aggressive, financially motivated 
The HC3 note said Hive conducts double extortion, with data theft prior to encryption, and support it with a data leak site accessible on the dark web.
“They operate via the ransomware as a service (RaaS) model, which involves them focusing on development and operations of the ransomware and other partners/affiliates to obtain initial access to the victim infrastructure,” the HC3 note said.
Hive encrypted files end with a .hive, .key.hive or .key extension.
“Some victims have received phone calls from Hive to pressure them to pay and conduct negotiations,” the HC3 warning said. “Like some other ransomware variants, Hive searches victim systems for applications and processes which backup data and terminates or disrupts them. This includes deleting shadow copies, backup files, and system snapshots.”
HC3 also recommended prevention as the optimal defense against ransomware variants. 
HC3 published the Hive note on April 18.
The agency this month published a 
In March, HC3 issued an 
There were not specific or credible threats at the time, but HC3 said U.S. cybersecurity agencies fully expect Conti’s aggressive hacking to continue.
Newsletter
Stay informed and empowered with Medical Economics enewsletter, delivering expert insights, financial strategies, practice management tips and technology trends — tailored for today’s physicians.



















