Lives Are At Stake As More US Hospitals Are Hacked

 US government agencies have warned that hospitals across the US have been hit by an aggressive ransomware campaign originating from N. Korea since 2021. 

The number of ransomware attacks on US healthcare organisations has increased by 94% from 2021 to 2022, according to a report from leading cyber security firm Sophos.

Some ransomware gangs pledged to not target medical facilities during the COVID-19 pandemic, but hospitals are still getting hit. Vitally, these attacks don't just affect  IT systems.

Ransomware attacks, in which criminal hackers encrypt computer networks and demand payment to make them functional again, have been a growing concern for both the private and public sector since the 90s. But they can be particularly devastating in the healthcare industry, where even a few minutes of downtime can have deadly consequences and have become ominously frequent.

Ransomware attacks on healthcare are particularly common in the US, with 41% of such attacks globally having been carried out against US-based firms in 2021. “The current outlook is terrible,” said Israel Barak, CISO of Cybereason. “We are seeing the industry experience an extremely sharp increase in both the quantity and level of sophistication of these attacks.”

Ransomware attacks have caused major healthcare disruptions, including delayed chemotherapy treatments and ambulances being diverted after computer systems were frozen. In 2021, a lawsuit filed by the mother of a baby who died in Alabama was the first “death by ransomware”, blaming a 2019 hack of a hospital for fatal brain damage of the newborn after heart rate monitors failed.

The potentially devastating consequences for medical facilities may be one of the reasons hackers have identified them as a high-profile target. 

The Cybersecurity and Infrastructure Security Agency (CISA) advise hospitals against paying ransoms, but providers often feel they have no choice. In 2021, 61% of healthcare organisations that suffered a ransomware attack paid the ransom, the highest percentage of any industry sector. “The North Korean state-sponsored cyber actors likely assume healthcare organisations are willing to pay ransoms because these organisations provide services that are critical to human life and health,” according to Barak. “When lives are at stake, it makes the decision very easy,” Barak said. “These attackers have identified medical organisations as very, very good targets because they are more likely to pay.” he said.

Attacks are typically carried out by private groups of criminals. In the third quarter of 2021, 30% of ransomware attacks on healthcare entities were carried out by Conti, a crime syndicate thought to be based in Russia, according to an industry report from cyber security firm BreachQuest. However, the recent incidents attributed to N Korea are just the latest state actor to orchestrate ransomware attacks on healthcare organisations.

The healthcare industry has been hit by a perfect storm of factors that have escalated the ransomware problem, with patient information is increasingly being digitised as hospitals struggle with small internet security budgets.

In 2009, the Obama administration passed a bill requiring all public and private healthcare providers to adopt electronic medical records by 2014, resulting in a massive migration of paper patient records to online systems. Today, just 4-7% of the average healthcare provider’s annual IT budget is focused on cyber security, the BreachQuest study said. The move was accelerated by the pandemic, he added, as more providers shifted online to connect with patients during lockdown and hospital staff were stretched thin by the influx of very ill  patients.

CISA has advised a “3-2-1 backup approach” for healthcare entities, including saving three copies of each type of data in two different formats, including one offline. But the CISA advisory to hospitals is “somewhat unhelpful”, said Vincent Berk, chief security officer at the cyber security firm Quantum Xchange, offering generic recommendations about securing data with little clear path to doing so. “The issue with this attack, and any other ransomware attack, is that the cure doesn’t really exist,” he said. “In other words, if it happens, it is already too late.” he said.

Sophos:     NBC:     Guardian:    ISC2:     CBS:     Techtarget:     AHA Innovation:    

You Might Also Read: 

Cyber Attack On US Children's Hospital:

 

« FBI Issues A Warning To Users Of Crypto Currency Apps
Magecart Attacks Hit Hundreds Of US Restaurants »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

NSFOCUS Information Technology

NSFOCUS Information Technology

NSFOCUS is a global service provider and enterprise DDoS mitigation solution provider.

Datto

Datto

Datto delivers a single toolbox of easy to use products and services designed specifically for managed service providers and the businesses they serve.

National Information Technology Development Agency (NITDA) - Nigeria

National Information Technology Development Agency (NITDA) - Nigeria

The National Information Technology Development Agency (NITDA) is committed to implementing the Nigerian National Information Technology Policy.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

DFI

DFI

DFI is a global leading provider of high-performance computing technology across multiple embedded industries.

Orca Security

Orca Security

Orca Security delivers full stack visibility including prioritized alerts to vulnerabilities, compromises, misconfigurations, and more across your entire inventory on all your cloud accounts.

AuthLite

AuthLite

With AuthLite, you can keep using all your existing software, with added two-factor authentication security placed exactly where you need it.

United Network Technologies

United Network Technologies

United Network Technologies is a leading Managed Services Provider, distributor and developer of specialised cyber security components and technologies.

InferSight

InferSight

InferSight can help you design an architecture that takes into account security, performance, availability, functionality, resiliency and future capacity to avoid technological lock in and limitations

Contechnet Deutschland

Contechnet Deutschland

Contechnet Deutschland started as a specialist in the area of IT disaster recovery and has since broadened its portfolio into information security and data protection.

In-Q-Tel (IQT)

In-Q-Tel (IQT)

IQT is the non-profit strategic investor that accelerates the development and delivery of cutting-edge technologies to U.S. government agencies that keep our nation safe.

Pixee

Pixee

Pixee fixes vulnerabilities, hardens code, squashes bugs, and gives engineers more time to focus on the work that counts.

Pvotal Technologies

Pvotal Technologies

Pvotal Technologies engineer complex, automated processes aligned with best AIOps, BizDevOps, DevSecOps, CloudOps, and ITOps practices.

WaveLink

WaveLink

WaveLink offers low risk, results-oriented Engineering Services and best-of-class Technical Support Services. Areas of expertise include cyber and security engineering.

Genix Cyber

Genix Cyber

Genix Cyber provides world-class cybersecurity services that protect systems, cloud applications, infrastructure, critical data, and networks from evolving cyber threats.

Panasonic Automotive Systems

Panasonic Automotive Systems

Panasonic Automotive Systems brings together security technologies and human resources cultivated across an extensive range of businesses into the automotive field.