On February 12, criminals used compromised credentials to remotely get entry to a Alternate Healthcare Citrix portal, an utility used to allow far off get entry to to desktops. The portal didn’t have multi-factor authentication. As soon as the danger actor won get entry to, they moved laterally throughout the methods in additional refined tactics and exfiltrated information. Ransomware was once deployed 9 days later.