← Back to news

Payload Ransomware claims the hack of Royal Bahrain Hospital

Security Affairs15/03/2026, 14:55
Read full article →

Summary

AI-Generated

Key Points:

  • Payload Ransomware has claimed responsibility for a breach at the Royal Bahrain Hospital, stealing 110 GB of sensitive data and threatening to release it unless a ransom is paid by March 23.
  • The impact includes potential exposure of patient data and disruption to healthcare services, affecting not only Bahrain but also neighboring countries like Oman, Qatar, Saudi Arabia, and the UAE.
  • Immediate actions recommended include isolating affected systems, enhancing monitoring for unusual activity, and preparing incident response plans for potential data leaks.

Technical Details: The ransomware employs ChaCha20 for file encryption and Curve25519 for key exchange while also deleting shadow copies and disabling security tools to hinder recovery efforts.

MITRE ATT&CK Techniques:

  • T1486 - Data Encrypted for Impact (Impact)
  • T1490 - Inhibit System Recovery (Impact)
  • T1562.001 - Impair Defenses: Disable or Modify Tools (Defense Evasion)

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.