The FBI has observed and responded to multiple Maui ransomware incidents at HPH Sector organizations.
North Korean state-sponsored cyber actors used Maui ransomware in these incidents to encrypt servers responsible for healthcare services-including electronic health records services, diagnostics services, imaging services, and intranet services.
In some cases, these incidents disrupted the services provided by the targeted HPH Sector organizations for prolonged periods.
The initial access vector(s) for these incidents is unknown.