Rhysida has listed Lurie Children's Hospital in Chicago on its dark-web extortion site, claiming theft of 600 GB of data and demanding 60 BTC ($3,700,000) from a single buyer. The attack earlier in the month forced the pediatric provider to shut down IT systems and delay care, with email, phones, MyChart and clinical services disrupted. As of February 22, 2024, restoration was still underway and several operational areas remained affected.

How care delivery was disrupted

Lurie is a leading pediatric acute care institution in the U.S. that provides care to over 200,000 children annually. After the intrusion, the hospital disconnected its technology environment and deferred some medical services. Electronic mail, telephone service, MyChart access and on-site internet connectivity were all degraded. Access to ultrasound and CT scan results was lost, triage and prioritization platforms went down, and physicians returned to handwritten prescriptions. Details of the initial response that took systems offline describe the same widespread outage.

Extortion claim and ransom terms

The group added Lurie Children's to its dark-web extortion portal, asserting it had exfiltrated 600 GB from the hospital. It offered the archive to one purchaser for 60 BTC ($3,700,000). A seven-day countdown was attached to the listing, after which Rhysida said it would either divide the material among multiple buyers at a reduced price or publish it openly on its platform.

Recovery status on February 22, 2024

According to the hospital's February 22, 2024 update, work to rebuild IT functions continued while interruptions persisted across parts of operations. Families were asked to carry paper copies of insurance cards and bring children's medication bottles to visits because the records system holding that information remained down. MyChart stayed inaccessible and waiting periods ran longer than normal while prescriptions continued to be prepared manually. Certain procedures and visits faced cancellation or rescheduling to preserve capacity for urgent cases. Billing infrastructure was also affected, so deadlines for settling medical bills were prolonged for the duration of the outage, and no-show fees were suspended.

Decryptor flaw context

Recently, researchers in Korea disclosed complete information on an encryptor weakness that allowed file recovery without payment, described in reporting on the free Rhysida ransomware decryptor for Windows that exploits an RNG flaw. The prolonged outage at Lurie Children's suggests the decryptor that law enforcement had used privately for many months may be ineffective against the group's latest attacks. If Rhysida's exfiltration claim is correct, sensitive medical data belonging to a large population of children would be permanently exposed to criminals.

Technical background (general)

This incident follows the double-extortion pattern now common in ransomware operations: encrypt local systems to interrupt care delivery while threatening to sell or release copied data to compel payment. Defenders typically respond by isolating affected hosts from the network, preserving logs and encrypted samples for analysis, rebuilding from known-clean backups, and rotating credentials before reconnecting services. Separate, offline backups and network segmentation limit how far both encryption and theft can spread.