SSK Plastic Surgery discloses it experienced a hack and extortion attempt in 2024:
https://databreaches.net/2025/03/08/ssk-plastic-surgery-discloses-it-experienced-a-hack-and-extortion-attempt-in-2024/
Plastic surgery groups tend to store a lot of patient data that is extremely sensitive.... and with pictures and videos.
In 2023, I wrote to the American Society of Plastic Surgeons and urged them to issue a guidance or article to their members about NOT attaching patients' names as filenames to nude photos and to storing patient data more securely.
AFAIK, they did NOT follow up by warning members NOT to store nude photos with patient names. They issued an alert about phishing.
And so the problem continues.... the New York Plastic Surgical Group got hit in January 2024, and then Jaime Schawartz, MD got hit in March 2024 as did SSK Plastic Surgery. How many more plastic surgery groups will we read about?
And for those who don't already know: some of the leak sites are STILL online and exposing nude patient photos and/or files with PII and PHI. In some cases, the threat actors encourage patients to contact them directly to pay to have their data removed. One group was initially charging patients $2500. They now charge about $500 for removal.
Aaargh...
#databreach #ransomware #plasticsurgery #extortion
I wish @cisacyber and the @FBI would issue a warning to plastic surgery groups specific to this issue.