Lives Are At Stake As More US Hospitals Are Hacked

 US government agencies have warned that hospitals across the US have been hit by an aggressive ransomware campaign originating from N. Korea since 2021. 

The number of ransomware attacks on US healthcare organisations has increased by 94% from 2021 to 2022, according to a report from leading cyber security firm Sophos.

Some ransomware gangs pledged to not target medical facilities during the COVID-19 pandemic, but hospitals are still getting hit. Vitally, these attacks don't just affect  IT systems.

Ransomware attacks, in which criminal hackers encrypt computer networks and demand payment to make them functional again, have been a growing concern for both the private and public sector since the 90s. But they can be particularly devastating in the healthcare industry, where even a few minutes of downtime can have deadly consequences and have become ominously frequent.

Ransomware attacks on healthcare are particularly common in the US, with 41% of such attacks globally having been carried out against US-based firms in 2021. “The current outlook is terrible,” said Israel Barak, CISO of Cybereason. “We are seeing the industry experience an extremely sharp increase in both the quantity and level of sophistication of these attacks.”

Ransomware attacks have caused major healthcare disruptions, including delayed chemotherapy treatments and ambulances being diverted after computer systems were frozen. In 2021, a lawsuit filed by the mother of a baby who died in Alabama was the first “death by ransomware”, blaming a 2019 hack of a hospital for fatal brain damage of the newborn after heart rate monitors failed.

The potentially devastating consequences for medical facilities may be one of the reasons hackers have identified them as a high-profile target. 

The Cybersecurity and Infrastructure Security Agency (CISA) advise hospitals against paying ransoms, but providers often feel they have no choice. In 2021, 61% of healthcare organisations that suffered a ransomware attack paid the ransom, the highest percentage of any industry sector. “The North Korean state-sponsored cyber actors likely assume healthcare organisations are willing to pay ransoms because these organisations provide services that are critical to human life and health,” according to Barak. “When lives are at stake, it makes the decision very easy,” Barak said. “These attackers have identified medical organisations as very, very good targets because they are more likely to pay.” he said.

Attacks are typically carried out by private groups of criminals. In the third quarter of 2021, 30% of ransomware attacks on healthcare entities were carried out by Conti, a crime syndicate thought to be based in Russia, according to an industry report from cyber security firm BreachQuest. However, the recent incidents attributed to N Korea are just the latest state actor to orchestrate ransomware attacks on healthcare organisations.

The healthcare industry has been hit by a perfect storm of factors that have escalated the ransomware problem, with patient information is increasingly being digitised as hospitals struggle with small internet security budgets.

In 2009, the Obama administration passed a bill requiring all public and private healthcare providers to adopt electronic medical records by 2014, resulting in a massive migration of paper patient records to online systems. Today, just 4-7% of the average healthcare provider’s annual IT budget is focused on cyber security, the BreachQuest study said. The move was accelerated by the pandemic, he added, as more providers shifted online to connect with patients during lockdown and hospital staff were stretched thin by the influx of very ill  patients.

CISA has advised a “3-2-1 backup approach” for healthcare entities, including saving three copies of each type of data in two different formats, including one offline. But the CISA advisory to hospitals is “somewhat unhelpful”, said Vincent Berk, chief security officer at the cyber security firm Quantum Xchange, offering generic recommendations about securing data with little clear path to doing so. “The issue with this attack, and any other ransomware attack, is that the cure doesn’t really exist,” he said. “In other words, if it happens, it is already too late.” he said.

Sophos:     NBC:     Guardian:    ISC2:     CBS:     Techtarget:     AHA Innovation:    

You Might Also Read: 

Cyber Attack On US Children's Hospital:

 

« FBI Issues A Warning To Users Of Crypto Currency Apps
Magecart Attacks Hit Hundreds Of US Restaurants »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Axis Capital

Axis Capital

AXIS Insurance’s Professional Lines Division is a leading underwriter of technology/cyber coverage and other specialty products around the globe.

Adlink Technology

Adlink Technology

ADLINK is a leading provider of embedded computing products and services for applications including IoT and industrial automation.

Matta

Matta

Matta is a cyber security consulting company providing information security services and solutions including vulnerability assessments, penetration testing and emergency response.

Block Armour

Block Armour

Block Armour is a Mumbai and Singapore based venture focused on harnessing emerging technologies to counter growing Cybersecurity challenges in bold new ways.

Philippine National Police Anti-Cybercrime Group (PNP-ACG)

Philippine National Police Anti-Cybercrime Group (PNP-ACG)

The mission of the PNP Anti-Cybercrime Group is to implement and enforce pertinent laws on cybercrime and other cyber related crimes and pursue an effective anti-cybercrime campaign.

Cyber Craft

Cyber Craft

CyberCraft is an innovative and dynamic software development, outsourcing and consulting company. Services offered include penetration testing.

Spanish Network of Excellence on Cybersecurity Research (RENIC)

Spanish Network of Excellence on Cybersecurity Research (RENIC)

RENIC is a membership based sectoral association that includes research centers and other agents of the research cybersecurity ecosystem in Spain.

Malleum

Malleum

MALLEUM are specialists in penetration testing and security assessments. We think like hackers – and act like them – to disclose discreet dangers to your organization.

Ensighten

Ensighten

Ensighten is a leader in Website Security & Privacy Compliance. Protect your website from malicious attacks, monitor & detect vulnerabilities, protect consumer data.

Towerwall

Towerwall

Towerwall offers a comprehensive suite of security services and solutions using best-of-breed tools and information security services.

TriagingX

TriagingX

TriagingX successfully created the first generation malware sandbox that is being used by many Fortune 500 companies for daily malware analysis.

AirEye

AirEye

AirEye is a leader in Network Airspace Protection (NAP). Block attacks against your corporate network launched from wireless devices in your corporate network airspace.

DoControl

DoControl

DoControl gives organizations the automated, self-service tools they need for SaaS applications data access monitoring, orchestration, and remediation.

Tsaaro Academy

Tsaaro Academy

Tsaaro Academy is a unique privacy certification training platform and here you earn a privacy certification CEH, CISM and DPO from India’s No.1 Privacy training platform.

CyTwist

CyTwist

CyTwist is an early warning attack detection platform that complement your existing security suite and provides your security teams with unique detection capabilities of stealth targeted attacks.

RAH Infotech

RAH Infotech

RAH Infotech is India’s leading value added distributor and solutions provider in the Network and Security domain. We are specialists in Enterprise and App Security and Application Delivery.