{"id":215,"date":"2023-03-01T08:45:39","date_gmt":"2023-03-01T14:45:39","guid":{"rendered":"https:\/\/kentprotect.com\/?p=215"},"modified":"2023-03-06T09:55:51","modified_gmt":"2023-03-06T15:55:51","slug":"reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web","status":"publish","type":"post","link":"https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/","title":{"rendered":"Reventics&#8217;s 2022 potential Royal ransomware incident affects 250,000+ patients, partial leak on dark web"},"content":{"rendered":"<div class='booster-block booster-read-block'><\/div>\n<p class=\"wp-block-paragraph\">(Image source: Reventics, 2021)<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>One-sentence summary: <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reventics, LLC, an Omega Healthcare subsidiary, was allegedly attacked by the Royal ransomware group in 2022, resulting in the potential breach of over 250,000+ patient records. <\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Who was involved?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Allegedly the Royal ransomware group, Reventics, and 250,000+ patients. <\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>What was the timeline?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">December 15, 2022: Breach starts and Reventics detects the breach. Breach allegedly ends the same day. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">December 27, 2022: Third-party incident response team confirms the details of the breach (Reventics, n.d., para. 2). <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">February 10, 2023: Reventics reports the breach to HHS (HHS, 2023). <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">February 13, 2023: Royal ransomware group allegedly leaks 16GB of the breached data on the dark web (<em>Ransomware Posts<\/em>, 2023). <\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>What occurred?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In December 2022, Reventics was allegedly hacked by the Royal ransomware group (Reventics, n.d., para. 2; Eurepoc, 2023; ThreatMon Ransomware Monitoring, 2023). The breach quickly ends after Reventics brings in an &#8220;international cybersecurity and forensic consulting firm,&#8221; who helped &#8220;quickly contain&#8221; the incident and &#8220;continue operations uninterrupted&#8221; (Attorney General of Montana, 2023; Reventics, 2023, p. 1; Reventics, n.d., para. 3). The Royal ransomware group appears to claim responsibility for the breach on the dark web and has posted 16GB of (partial) data there (ThreatMon Ransomware Monitoring, 2023; HackNotice, 2023; <em>Ransomware Posts<\/em>, 2023). Breached data included both PHI and PII, including: &#8220;first and last name, data of birth, social security number, financial information, healthcare provider&#8217;s name and address, health plan name, clinical data&#8221; and billing codes (Reventics, n.d., para. 2). <\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Estimated costs:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Outside incident response costs plus notification costs. 12 hour M-F call center (Reventics, n.d., para. 4). Identity management services: &#8220;12 months of credit and CyberScan monitoring, a $1,000,000 insurance reimbursement policy, and fully managed id theft recovery services&#8221; (Reventics, 2023, p. 1). <\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Involved laws: <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Federal: HIPAA and HITECH <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">State: Mont. Code Ann. \u00a7 30-14-1704 <\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Root cause: <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">TBA or N\/A (see disclaimer) <\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Lessons learned: <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">TBA or N\/A (see disclaimer) <\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Commentary: <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reventics refers to the threat actor as a &#8220;cyber-intruder who encrypted and potentially accessed sensitive information&#8221; (Reventics, 2023, p. 1). However, as a cybersecurity professional, it is obvious that a threat actor is only going to encrypt as a significant event in a breach in order to ransom the victims (other than to transport\/exfiltrate the files through an encrypted channel or protocol such as TLS). Thus, this came off as omitting something larger and warranted deeper investigation, which did confirm a ransomware group was allegedly claiming responsibility for the event. <\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Sources: <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attorney General of Montana. (2023, February 10). <em>REPORTED DATA BREACH INCIDENTS<\/em>. Montana Department of Justice. Retrieved March 1, 2023, from https:\/\/dojmt.gov\/consumer\/databreach\/<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Eurepoc. (2023, February 20). <em>Potential criminal actor gained access to the network of healthcare provider Reventics and stole patient information in December 2022 | EuRepoC: European Repository on Cyber Incidents<\/em>. European Respository of Cyber Incidents. Retrieved March 1, 2023, from https:\/\/eurepoc.eu\/incident\/potential-criminal-actor-gained-access-to-the-network-of-healthcare-provider-reventics-and-stole-patient-information-in-december-2022-1<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">HackNotice. (2023, February 12). <em>HackNotice: Reventics Hack<\/em>. hacknotice.com. Retrieved March 1, 2023, from https:\/\/app.hacknotice.com\/<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">HHS. (2023, February 10). <em>U.S. Department of Health &amp; Human Services &#8211; Office for Civil Rights<\/em>. Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information. Retrieved March 1, 2023, from https:\/\/ocrportal.hhs.gov\/ocr\/breach\/breach_report.jsf<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Ransomware Posts<\/em>. (2023, February 13). github.io. Retrieved March 1, 2023, from https:\/\/privtools.github.io\/ransomposts\/<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reventics. (n.d.). <em>notice-of-data-security-incident.png<\/em>. Reventics.com. https:\/\/reventics.com\/images\/email-images\/notice-of-data-security-incident.png<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reventics. (2021, February). <em>reventics-logo-for-cerner-apps-v2.jpg<\/em>. cerner.com. https:\/\/code.cerner.com\/-\/media\/code-media-folder\/apps\/reventics\/feb2021\/reventics-logo-for-cerner-apps-v2.jpg?vs=5<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reventics. (2023). Notice of Data Security Incident. In <em>REPORTED DATA BREACH INCIDENTS<\/em>. Montana Department of Justice. Retrieved March 1, 2023, from https:\/\/dojmt.gov\/wp-content\/uploads\/Consumer-notification-letter-62.pdf<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ThreatMon Ransomware Monitoring. (2023, February 13). <em>ThreatMon Ransomware Monitoring on<\/em>. Twitter. Retrieved March 1, 2023, from https:\/\/twitter.com\/TMRansomMonitor\/status\/1625205879980101663<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-4-3 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Reventics 2022 potential Royal ransomware incident affects 250,000+ patients, partial leak available\" width=\"640\" height=\"480\" src=\"https:\/\/www.youtube.com\/embed\/Hqwe7e2SjXo?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\">YouTube\/Blog Notification Post<\/figcaption><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>(Image source: Reventics, 2021) One-sentence summary: Reventics, LLC, an Omega Healthcare subsidiary, was allegedly attacked by the Royal<\/p>\n","protected":false},"author":4,"featured_media":216,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[205,3,12,13,76,204,63,75,61,11,10,77,74,202,14,201,207,69,71,43,206,72,70,8,27,182,167,67,119,203,199,200,62,15],"class_list":["post-215","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-breach-report","tag-billing","tag-breach-report","tag-breaches","tag-ciso","tag-cloud","tag-colorado-healthcare","tag-computer-security","tag-cyber-security","tag-cybercrime","tag-cybersecurity","tag-dallas","tag-dark-web","tag-data-breach","tag-encryption","tag-executive","tag-exfiltration","tag-greenwoodvillage","tag-have-been-pwned","tag-have-i-pwned","tag-hipaa","tag-hitech-been-pwned","tag-i-been-pwned","tag-i-have-been-pwned","tag-kent-protect","tag-kentprotect","tag-leak","tag-press","tag-pwned","tag-ransomware","tag-reventics","tag-royal","tag-royalransomware","tag-security","tag-summary"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Reventics&#039;s 2022 potential Royal ransomware incident affects 250,000+ patients, partial leak on dark web - Kent Protect<\/title>\n<meta name=\"description\" content=\"Reventics, LLC, an Omega Healthcare subsidiary, was allegedly attacked by the Royal ransomware group in 2022, resulting in the potential breach of over 250,000+ patient records.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Reventics&#039;s 2022 potential Royal ransomware incident affects 250,000+ patients, partial leak on dark web - Kent Protect\" \/>\n<meta property=\"og:description\" content=\"Reventics, LLC, an Omega Healthcare subsidiary, was allegedly attacked by the Royal ransomware group in 2022, resulting in the potential breach of over 250,000+ patient records.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/\" \/>\n<meta property=\"og:site_name\" content=\"Kent Protect\" \/>\n<meta property=\"article:published_time\" content=\"2023-03-01T14:45:39+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-03-06T15:55:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/03\/reventics-logo-for-cerner-apps-v2.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"676\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Kyler Kent CISSP\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kyler Kent CISSP\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/03\\\/01\\\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/03\\\/01\\\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\\\/\"},\"author\":{\"name\":\"Kyler Kent CISSP\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#\\\/schema\\\/person\\\/f9b4d76bd2f5b5559a08ad2e004a1116\"},\"headline\":\"Reventics&#8217;s 2022 potential Royal ransomware incident affects 250,000+ patients, partial leak on dark web\",\"datePublished\":\"2023-03-01T14:45:39+00:00\",\"dateModified\":\"2023-03-06T15:55:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/03\\\/01\\\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\\\/\"},\"wordCount\":609,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/03\\\/01\\\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/reventics-logo-for-cerner-apps-v2.jpg\",\"keywords\":[\"billing\",\"breach report\",\"breaches\",\"ciso\",\"cloud\",\"colorado healthcare\",\"computer security\",\"cyber security\",\"cybercrime\",\"cybersecurity\",\"dallas\",\"dark web\",\"data breach\",\"encryption\",\"executive\",\"exfiltration\",\"greenwoodvillage\",\"have been pwned\",\"have I pwned\",\"HIPAA\",\"Hitech been pwned\",\"I been pwned\",\"I have been pwned\",\"kent protect\",\"kentprotect\",\"leak\",\"press\",\"pwned\",\"ransomware\",\"reventics\",\"royal\",\"royalransomware\",\"security\",\"summary\"],\"articleSection\":[\"The Breach Report!\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/03\\\/01\\\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/03\\\/01\\\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\\\/\",\"url\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/03\\\/01\\\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\\\/\",\"name\":\"Reventics's 2022 potential Royal ransomware incident affects 250,000+ patients, partial leak on dark web - Kent Protect\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/03\\\/01\\\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/03\\\/01\\\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/reventics-logo-for-cerner-apps-v2.jpg\",\"datePublished\":\"2023-03-01T14:45:39+00:00\",\"dateModified\":\"2023-03-06T15:55:51+00:00\",\"description\":\"Reventics, LLC, an Omega Healthcare subsidiary, was allegedly attacked by the Royal ransomware group in 2022, resulting in the potential breach of over 250,000+ patient records.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/03\\\/01\\\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/03\\\/01\\\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/03\\\/01\\\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\\\/#primaryimage\",\"url\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/reventics-logo-for-cerner-apps-v2.jpg\",\"contentUrl\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/reventics-logo-for-cerner-apps-v2.jpg\",\"width\":1024,\"height\":676,\"caption\":\"Reventics Logo for Cerner Apps\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/2023\\\/03\\\/01\\\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/kentprotect.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Reventics&#8217;s 2022 potential Royal ransomware incident affects 250,000+ patients, partial leak on dark web\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#website\",\"url\":\"https:\\\/\\\/kentprotect.com\\\/\",\"name\":\"Kent Protect\",\"description\":\"Starring the Breach Report! and other security and cybersecurity series\",\"publisher\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/kentprotect.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#organization\",\"name\":\"Kent Protect\",\"url\":\"https:\\\/\\\/kentprotect.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/cropped-FullLogo_Transparent-1-with-KP-Smaller.png\",\"contentUrl\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/04\\\/cropped-FullLogo_Transparent-1-with-KP-Smaller.png\",\"width\":209,\"height\":161,\"caption\":\"Kent Protect\"},\"image\":{\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/#\\\/schema\\\/person\\\/f9b4d76bd2f5b5559a08ad2e004a1116\",\"name\":\"Kyler Kent CISSP\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/Retry-3-150x150.jpg\",\"url\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/Retry-3-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/kentprotect.com\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/Retry-3-150x150.jpg\",\"caption\":\"Kyler Kent CISSP\"},\"description\":\"Kyler Kent is a Senior Cybersecurity Analyst on CrowdStrike\u2019s Falcon Complete MDR team, where he helps large enterprises detect, investigate, and contain real intrusions across cloud and hybrid environments. His work spans threat hunting, incident response, and security automation\u2014turning noisy telemetry into clear, repeatable actions that reduce risk quickly. Previously, Kyler served as a Threat Hunting and Intelligence Specialist supporting a critical infrastructure provider in Dallas, and led security automation and operational coordination at CyberConvoy. He holds a Master\u2019s in Cybersecurity Risk Management from Georgetown University and maintains certifications including CISSP, AWS Solutions Architect \u2013 Professional, AWS Security \u2013 Specialty, and multiple CrowdStrike credentials. He writes to close the gap between \u201cwhat the textbook says\u201d and what analysts actually do on shift with his published book: \\\"SOC Analyst Career Guide\\\" (ISBN-13: 9781835467466). https:\\\/\\\/linktr.ee\\\/kentprotect.com Corrections: corrections@kentprotect.com\",\"sameAs\":[\"http:\\\/\\\/kylerkent.com\"],\"url\":\"https:\\\/\\\/kentprotect.com\\\/index.php\\\/author\\\/kylerkent\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Reventics's 2022 potential Royal ransomware incident affects 250,000+ patients, partial leak on dark web - Kent Protect","description":"Reventics, LLC, an Omega Healthcare subsidiary, was allegedly attacked by the Royal ransomware group in 2022, resulting in the potential breach of over 250,000+ patient records.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/","og_locale":"en_US","og_type":"article","og_title":"Reventics's 2022 potential Royal ransomware incident affects 250,000+ patients, partial leak on dark web - Kent Protect","og_description":"Reventics, LLC, an Omega Healthcare subsidiary, was allegedly attacked by the Royal ransomware group in 2022, resulting in the potential breach of over 250,000+ patient records.","og_url":"https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/","og_site_name":"Kent Protect","article_published_time":"2023-03-01T14:45:39+00:00","article_modified_time":"2023-03-06T15:55:51+00:00","og_image":[{"width":1024,"height":676,"url":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/03\/reventics-logo-for-cerner-apps-v2.jpg","type":"image\/jpeg"}],"author":"Kyler Kent CISSP","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Kyler Kent CISSP","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/#article","isPartOf":{"@id":"https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/"},"author":{"name":"Kyler Kent CISSP","@id":"https:\/\/kentprotect.com\/#\/schema\/person\/f9b4d76bd2f5b5559a08ad2e004a1116"},"headline":"Reventics&#8217;s 2022 potential Royal ransomware incident affects 250,000+ patients, partial leak on dark web","datePublished":"2023-03-01T14:45:39+00:00","dateModified":"2023-03-06T15:55:51+00:00","mainEntityOfPage":{"@id":"https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/"},"wordCount":609,"commentCount":0,"publisher":{"@id":"https:\/\/kentprotect.com\/#organization"},"image":{"@id":"https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/#primaryimage"},"thumbnailUrl":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/03\/reventics-logo-for-cerner-apps-v2.jpg","keywords":["billing","breach report","breaches","ciso","cloud","colorado healthcare","computer security","cyber security","cybercrime","cybersecurity","dallas","dark web","data breach","encryption","executive","exfiltration","greenwoodvillage","have been pwned","have I pwned","HIPAA","Hitech been pwned","I been pwned","I have been pwned","kent protect","kentprotect","leak","press","pwned","ransomware","reventics","royal","royalransomware","security","summary"],"articleSection":["The Breach Report!"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/","url":"https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/","name":"Reventics's 2022 potential Royal ransomware incident affects 250,000+ patients, partial leak on dark web - Kent Protect","isPartOf":{"@id":"https:\/\/kentprotect.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/#primaryimage"},"image":{"@id":"https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/#primaryimage"},"thumbnailUrl":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/03\/reventics-logo-for-cerner-apps-v2.jpg","datePublished":"2023-03-01T14:45:39+00:00","dateModified":"2023-03-06T15:55:51+00:00","description":"Reventics, LLC, an Omega Healthcare subsidiary, was allegedly attacked by the Royal ransomware group in 2022, resulting in the potential breach of over 250,000+ patient records.","breadcrumb":{"@id":"https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/#primaryimage","url":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/03\/reventics-logo-for-cerner-apps-v2.jpg","contentUrl":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/03\/reventics-logo-for-cerner-apps-v2.jpg","width":1024,"height":676,"caption":"Reventics Logo for Cerner Apps"},{"@type":"BreadcrumbList","@id":"https:\/\/kentprotect.com\/index.php\/2023\/03\/01\/reventics-2022-potential-royal-ransomware-incident-affects-250000-patients-partial-leak-on-dark-web\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/kentprotect.com\/"},{"@type":"ListItem","position":2,"name":"Reventics&#8217;s 2022 potential Royal ransomware incident affects 250,000+ patients, partial leak on dark web"}]},{"@type":"WebSite","@id":"https:\/\/kentprotect.com\/#website","url":"https:\/\/kentprotect.com\/","name":"Kent Protect","description":"Starring the Breach Report! and other security and cybersecurity series","publisher":{"@id":"https:\/\/kentprotect.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/kentprotect.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/kentprotect.com\/#organization","name":"Kent Protect","url":"https:\/\/kentprotect.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/kentprotect.com\/#\/schema\/logo\/image\/","url":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/04\/cropped-FullLogo_Transparent-1-with-KP-Smaller.png","contentUrl":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/04\/cropped-FullLogo_Transparent-1-with-KP-Smaller.png","width":209,"height":161,"caption":"Kent Protect"},"image":{"@id":"https:\/\/kentprotect.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/kentprotect.com\/#\/schema\/person\/f9b4d76bd2f5b5559a08ad2e004a1116","name":"Kyler Kent CISSP","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/03\/Retry-3-150x150.jpg","url":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/03\/Retry-3-150x150.jpg","contentUrl":"https:\/\/kentprotect.com\/wp-content\/uploads\/2023\/03\/Retry-3-150x150.jpg","caption":"Kyler Kent CISSP"},"description":"Kyler Kent is a Senior Cybersecurity Analyst on CrowdStrike\u2019s Falcon Complete MDR team, where he helps large enterprises detect, investigate, and contain real intrusions across cloud and hybrid environments. His work spans threat hunting, incident response, and security automation\u2014turning noisy telemetry into clear, repeatable actions that reduce risk quickly. Previously, Kyler served as a Threat Hunting and Intelligence Specialist supporting a critical infrastructure provider in Dallas, and led security automation and operational coordination at CyberConvoy. He holds a Master\u2019s in Cybersecurity Risk Management from Georgetown University and maintains certifications including CISSP, AWS Solutions Architect \u2013 Professional, AWS Security \u2013 Specialty, and multiple CrowdStrike credentials. He writes to close the gap between \u201cwhat the textbook says\u201d and what analysts actually do on shift with his published book: \"SOC Analyst Career Guide\" (ISBN-13: 9781835467466). https:\/\/linktr.ee\/kentprotect.com Corrections: corrections@kentprotect.com","sameAs":["http:\/\/kylerkent.com"],"url":"https:\/\/kentprotect.com\/index.php\/author\/kylerkent\/"}]}},"_links":{"self":[{"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/posts\/215","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/comments?post=215"}],"version-history":[{"count":6,"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/posts\/215\/revisions"}],"predecessor-version":[{"id":225,"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/posts\/215\/revisions\/225"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/media\/216"}],"wp:attachment":[{"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/media?parent=215"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/categories?post=215"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kentprotect.com\/index.php\/wp-json\/wp\/v2\/tags?post=215"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}