North Korean Hackers Continue to Target US Healthcare

Use this page to get oriented quickly.

The brief below is a reading aid. The original source material and source link remain the governing reference.

Operational Brief

Lazarus Group hackers are using Medusa ransomware in extortion attacks on U.S. healthcare entities; Rim Jong Hyok, an alleged member of the Lazarus subgroup Stonefly, was indicted in 2024.

Why It Matters for Texas Credit Unions

The article does not mention Texas, TCUD, or any Texas-specific entities. The information pertains to U.S. healthcare entities generally.

Who this most likely affects

Bounded site guidance: This item is most likely relevant for credit unions with material information-security, technology, or vendor-management exposure.

Why this fit: The source language points to cyber, technology, or third-party oversight risk.

This is site guidance, not a formal determination. CU InfoSecurity and the original source material remain the governing reference.

Private Follow-Up

Save this for follow-up.

Sign in to keep a private note, target date, or reminder for this item.

Sign in to save this item Create account

Original Source Material

Report: Lazarus Group Pivoting to Medusa Ransomware for Extortion Attacks North Korean-state backed Lazarus Group hackers are using Medusa ransomware in extortion attacks on U.S. healthcare entities despite a 2024 U.S. indictment of Rim Jong Hyok, an alleged member of the Lazarus subgroup Stonefly, according to a new threat intelligence report.