Alabama Board of Nursing ransomware attack may have exposed personal information | #ransomware | #cybercrime

The Alabama Board of Nursing says a ransomware attack on its computer systems may have exposed sensitive personal and health information belonging to Alabama nurses, applicants, licensees and others who use the agency’s services.
The board said Friday that a forensic investigation found suspicious activity in its technology environment in August and confirmed malicious activity in portions of the system on September 1. Investigators determined that some data was collected and downloaded during the incident.
The board has not determined what information was accessed or how many people may have been affected. However, it said investigators found reason to believe sensitive personally identifying information and protected health information may have been exposed.
Potentially affected information includes names, dates of birth, the last four digits of Social Security numbers, driver’s license numbers, professional licensing information and medical information, according to the board.
The board said it contained the attack and prevented it from spreading further. It has been working with the Alabama Office of Information Technology, outside cybersecurity specialists and a third-party incident response team to investigate the incident and restore its systems.
The FBI and the Alabama Law Enforcement Agency are also involved in the investigation.
The cybersecurity incident has disrupted the board’s operations since September 1, with some services remaining unavailable as the agency works to restore its technology systems. The board has been bringing services back online in stages while reviewing and securing the affected systems.
The disruption also affected licensing and other administrative processes for nurses and applicants. The board has established alternative procedures for some applications and reports while its online systems remain unavailable.
The board is advising nurses, applicants and others who may have interacted with the agency to take precautions against identity theft and fraud.
Those steps include using multifactor authentication, particularly on email, financial, health care and employment accounts, and monitoring bank accounts, credit card statements, credit reports, insurance records and tax accounts for suspicious activity.
The board also recommends that individuals consider placing a credit freeze or fraud alert with the major credit reporting agencies.
Officials are warning nurses and other members of the public to be especially cautious about phishing and impersonation attempts related to the incident. The board said it will not ask for account credentials or passwords through unsolicited emails, text messages or telephone calls.
The agency said it will issue additional notifications or public updates as investigators learn more about the incident and recovery efforts continue.


