• News/
  • https://www.theregister.com/2025/05/30/fred_hutch_cancer_center_commits/

US medical org pays $50M+ to settle case after crims raided data and threatened to swat cancer patients

The Register
·
Connor Jones
·
Published May 30, 2025
·
Updated

A Seattle cancer facility has agreed to fork out around $52.5 million as part of a class action settlement linked to a Thanksgiving 2023 cyberattack where criminals directly threatened cancer patients with swat attacks. The Fred Hutchinson Cancer Center (Fred Hutch) disclosed its November 2023 attack a month later, after it confirmed that criminals had made off with personal and sensitive data, including health insurance information, patients' treatments, diagnoses, lab results, and more. That data was then used by the attackers in question to carry out highly aggressive extortion tactics, which according to the original class action complaint [PDF], allegedly included directly contacting some patients via email and threatening to swat them. The complaint claimed: The cybercriminals sending these emails demand that patients pay them to prevent the sale of that data.... The threatening emails also include specific examples of the personal data stolen and exposed for each individual recipient of the email, including their name, address, patient record number, and medical information. Further still, the emails threatened some recipients that if they did not pay the extortion demand, the hackers would initiate a swatting attack, "which occur[s] when a bogus claim is made to law enforcement so that emergency response officers, like SWAT teams, show up at a person's home. The FBI was called in. Cybercriminals often use pilfered data as a bargaining chip with the organization from w...

Read full article

Affected Software

1 affected component
Citrix Citrix
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a Seattle cancer facility's settlement of over $52 million following a cyberattack that threatened cancer patients.

2

What security implications are discussed in this article?

The article highlights the serious risks and consequences of data breaches in healthcare organizations, especially when patient safety is jeopardized.

3

What criminal activities are described in the article?

The article describes how criminals raided the data of a cancer facility and threatened to swat cancer patients.

4

What was the response of the US medical organization to the cyberattack?

The organization agreed to a settlement of approximately $52.5 million as part of a class action lawsuit.

5

Which products or software were identified as affected by the cyberattack?

The cyberattack involved vulnerabilities related to Citrix software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203