Booba Project Claims Breach of NY Gastroenterology Practice

Booba Project Ransomware Claims Attack on NY Healthcare Provider

HIGH
October 3, 2026
5m read
RansomwareData BreachThreat Actor

Impact Scope

Affected Companies

Associated Gastroenterologists of Central New York, P.C.

Industries Affected

Healthcare

Geographic Impact

United States (local)

Related Entities

Threat Actors

Booba Project

Other

Associated Gastroenterologists of Central New York, P.C.

Full Report

Executive Summary

A ransomware group identifying as "Booba Project" has claimed a cyberattack against Associated Gastroenterologists of Central New York, P.C., a medical practice based in New York. The group posted its claim on its dark web leak site around October 1, 2026, alleging the exfiltration of 70 gigabytes of sensitive data. While the healthcare provider has not issued a public statement, it has reportedly filed a data breach notification with the Vermont Attorney General's office, suggesting the claim is credible. The incident places sensitive patient and employee data at high risk of exposure and has already triggered investigations for class-action litigation.

Threat Overview

Booba Project appears to be a double-extortion ransomware operator. This tactic involves not only encrypting a victim's files but also stealing sensitive data beforehand. The threat to publish the stolen data on a public leak site is used as additional leverage to coerce victims into paying a ransom. The target, a specialized medical practice, is a high-value target for extortion due to the sensitive nature of the data it holds, including Protected Health Information (PHI).

The group's claim of stealing 70 GB of data is significant for a healthcare provider of this size and suggests a comprehensive breach of their network.

Technical Analysis

The specific TTPs used by the Booba Project in this attack are not yet public. However, the attack pattern is consistent with common ransomware campaigns:

  • Initial Access: Ransomware groups often gain access through exposed remote services like RDP, exploitation of unpatched vulnerabilities, or phishing campaigns.
  • Credential Access & Lateral Movement: Once inside, they would move laterally across the network, escalating privileges to gain access to domain controllers and file servers where critical data is stored. This often involves techniques like credential dumping (T1003 - OS Credential Dumping).
  • Data Exfiltration: Before deploying the ransomware, the actors would exfiltrate large volumes of data to an external server under their control (T1048 - Exfiltration Over Alternative Protocol).
  • Impact: Finally, they would execute the ransomware payload to encrypt files across the network (T1486 - Data Encrypted for Impact) and delete backups or Volume Shadow Copies to hinder recovery (T1490 - Inhibit System Recovery).

Impact Assessment

The potential impact of this data breach is severe for both the medical practice and its patients.

  • For Patients: The stolen data likely includes names, Social Security numbers, dates of birth, medical diagnoses, treatment histories, and health insurance information. This places them at high risk of identity theft, financial fraud, and highly targeted phishing attacks. The exposure of sensitive medical information is also a profound violation of privacy.
  • For the Provider: Associated Gastroenterologists of CNY faces significant operational disruption, financial costs for recovery, and severe regulatory and legal consequences. This includes potential fines under HIPAA for failing to protect PHI and costly class-action lawsuits from affected patients and staff. The reputational damage can also lead to a loss of patient trust.

IOCs — Directly from Articles

No specific Indicators of Compromise (IOCs) were provided in the source articles.

Cyber Observables — Hunting Hints

To hunt for similar ransomware activity, security teams in healthcare can look for:

Type
command_line_pattern
Value
wmic.exe shadowcopy delete
Description
A command to delete Volume Shadow Copies, a common precursor to file encryption by ransomware.
Context
Windows Event ID 4688, EDR command line logs.
Confidence
high
Type
file_name
Value
*.locked, *.encrypted
Description
Ransomware often appends a specific extension to encrypted files. Monitor for mass file renaming events.
Context
File Integrity Monitoring (FIM) systems, EDR logs.
Confidence
high
Type
file_name
Value
readme.txt, decrypt_me.html
Description
Common names for ransom notes dropped in directories with encrypted files.
Context
Monitor for the creation of files with these names across multiple systems.
Confidence
high

Detection & Response

  1. EDR and Antivirus: Ensure endpoint protection is configured to detect and block known ransomware behaviors, such as rapid file encryption and attempts to disable security services. D3-PA - Process Analysis is a core component of this.
  2. Network Monitoring: Monitor for large, unexpected data transfers to external IP addresses, which could indicate data exfiltration. D3-NTA - Network Traffic Analysis is crucial for this.
  3. Backup Integrity: Regularly monitor the status and integrity of backups to ensure they are not being tampered with or deleted.

Mitigation

Healthcare organizations must prioritize the following controls to defend against ransomware:

  1. Offline Backups: Maintain immutable or air-gapped backups of all critical data, including PHI. Regularly test the restoration process.
  2. Network Segmentation: Segment the network to prevent ransomware from spreading from workstations to critical servers hosting EMR/EHR systems (M1030 - Network Segmentation).
  3. Patch Management: Aggressively patch vulnerabilities, especially on internet-facing systems like VPNs and firewalls (M1051 - Update Software).
  4. Security Awareness Training: Train employees to identify and report phishing emails, which are a primary entry vector for ransomware attacks (M1017 - User Training).

Timeline of Events

1
October 1, 2026
The 'Booba Project' ransomware group claims the attack on its dark web leak site.
2
October 3, 2026
This article was published

MITRE ATT&CK Mitigations

Segment networks to separate critical systems like EMR/EHR databases from the general user network.

Mapped D3FEND Techniques:

Train staff to recognize and report phishing attempts, a common initial access vector for ransomware.

Deploy and maintain modern endpoint protection that uses behavioral analysis to detect ransomware activity.

Mapped D3FEND Techniques:

Timeline of Events

1
October 1, 2026

The 'Booba Project' ransomware group claims the attack on its dark web leak site.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

ransomwaredata breachhealthcarePHIHIPAA

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.