Qilin ransomware group claims hack of Palau Ministry of Health and Human Services
This domain name is currently parked with VentraIP.
Key points
- Qilin ransomware group claimed responsibility on February 20, 2025.
- Patient data compromised, including billing summaries, personal, and health information.
- MHHS confirmed cyberattack and ongoing investigation.
Connected intelligence
Signal brief
Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.
Organization
- Published
- Feb 20, 2025
- Updated
- Jul 22, 2026
- Confidence
- Medium
- Evidence
- 3 sources
Structured assessment
Signal analysis
This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.
Threat source
Watch ransomware, endpoint compromise and business interruption exposure.
- Source type: possible insider or internal misuse
Business impact
- Impact area
- Confidentiality, Availability
- Likely asset
- User or customer data
Mentioned entities
Quick context
Questions about this signal
What happened in this signal?
This domain name is currently parked with VentraIP. Get our Quarterly Ransomware Report as a PDF In February, we recorded the highest number of attacks ever for the month, reaching a total of 77, marking a 35% increase compared to last year. Government was the hardest hit sector, closely followed by the healthcare and services. 25 different gangs claimed responsibility for attacks this month, with RansomHub taking the top spot for most active variant, accounting for nearly 10% of the victims. Find out who made ransomware headlines in February: It was announced that Douglasville-Douglas County Water and Sewer Authority was hit by a malware attack in late 2024. Upon discovery of the incident immediate action was taken and the Emergency Response Plan was activated, ensuring minimal customer impact. The framework has since been rebuilt with minimal data loss. Lynx ransomware gang claimed the attack. CESI announced that it had been notified of a cybersecurity incident on February 1. A crisis unit was immediately activated, and internet access was cut off as a precautionary measure to contain the incident. Cybersecurity experts are working with CESI to analyse the impact and gradually restore services under optimal security conditions. Classes were not impacted by the attack. Termite ransomware group claimed responsibility for the attack. Details of a May 2024 cyberattack on Delta Health Memorial Hospital District finally came to light following a breach notification to the HHS. The healthcare provider stated that detection of the event occurred on May 30 th and that those impacted had been notified before the end of July. It was reported that 148,363 individuals were impacted by the event. External counsel for the healthcare provider also filed a breach notification, but some of the details between the two notices were contradictory. Two years after the incident took place, individuals have begun to be notified about personal information exposed during a ransomware attack on the City of Hayward . On December 30 th , 2024, officials learned that individual’s personal information including names, DOBs, SSNs, financial information, government IDs and healthcare information had been impacted. The attack disrupted aspects and components of computer systems and networks. As a response, impacted systems were taken offline for more than two weeks. Cicada3301 took responsibility for a ransomware attack on Rivers Casino Philadelphia , claiming to have stolen 2.56TB of confidential information. The casino acknowledged that it had fallen victim to unauthorized access to its computer services and later learned that some information may have been exfiltrated. Individuals whose SSNs and bank account information may have been compromised have been notified. Japanese sportswear company Mizuno confirmed that it had fallen victim to a ransomware attack orchestrated by BianLian. Malicious activity was first detected by Mizuno in November with a further investigation revealing that systems had been infiltrated since August, resulting in the exfiltration of individual’s PII. The number of individuals impacted has not yet been publicly released by Mizuno. In Texas, the city of McKinney informed thousands of residents that a cyberattack in October exposed sensitive information. The city stated that its government systems were breached on October 31 st , but security systems didn’t discover the attack until November 14. The city’s IT team “severed” unauthorized activity and contacted appropriate law enforcement. The city said that 17.751 of its 213,00 residents have been impacted by the breach. No ransomware gang has yet claimed responsibility for the incident. Prominent Indian technology design and systems engineering company Mistral Solutions Pvt. Ltd fell victim to a ransomware attack at the hands of Bashe. There is very little information available about this attack, but it has been reported that the ransomware gang gave Mistral Solutions around 7 days to pay an undisclosed ransom amount. Ransomware gang BianLian claimed responsibility for a November 2024 data breach at Clair Orthopaedics and Sports Medicine . The Michigan-based healthcare provider notified an undisclosed number of patients that data including PII, PHI, and financial information had been compromised as a result of the attack. BianLian claimed to have stolen 1.2TB of data from St. Clair. Birmingham-based engineering firm IMI revealed that it was stuck by a cyberattack involving unauthorized access to its systems. IMI declined to disclose what data had been accessed in the attack, but it is understood that systems in several of its locations worldwide were impacted. This incident was announced just one week after IMI’s rival Smith’s Group admitted to being victimized by a ransomware attack. 14,207 people have been notified about a October 2024 data breach involving Crystal Lake Elementary District 47 . The district stated that it experienced network disruption in mid-October, with an investigation revealing that certain information was accessed by unauthorized individuals. The school has not publicly disclosed what personal information was compromised, nor if it belonged to students or staff. RansomHub claimed the attack, allegedly exfiltrating 600GB of data. Community High School District 117 notified 18,830 people about a June 2024 data breach, claimed by BlackSuit ransomware gang. The notice issued by the district acknowledged that unauthorized access to its network occurred between June 2 and June 12, 2024, but did not confirm the claims made by the ransomware group. A ransomware attack shut down the internet and telephone systems at the University of The Bahamas , forcing changes on administrators, professors and students. The attacks began on February 2 nd and impacted all online applications including email platforms and systems used for classwork, forcing all online classes to be cancelled. The university worked to contain the spread of the attack and launched an investigation into the full scope of the incident. No ransomware group has yet taken credit for the attack. A December 2024 attack on Wayne-Westland Community Schools was claimed by RansomHub this month. Although the attack took place in late 2024, recovery remained ongoing throughout January, with key systems being brought back online on January 9th. Public information about this attack is limited.
When was this signal reported?
Shadow Tier lists Feb 20, 2025 as the signal date.
Which organization is connected to this signal?
Palauhealth is the organization connected to this public signal.
Explore PalauhealthWhich attack pattern is relevant?
This signal is connected to current ransomware incidents based on its reported incident context.
Explore current ransomware incidentsWhich impact area is relevant?
This signal is connected to data exposure and breach intelligence based on its reported consequences.
Explore data exposure and breach intelligence