Stolen NHS Data Published On The Dark Web

A ransomware group has carried out its threat against a Scottish health board and published a "large volume" of stolen data on the Dark Web. NHS Dumfries and Galloway was hit by a cyber attack in March and confirmed hackers were able to access a "significant quantity of data", including patient and staff-identifiable information.

The cyber criminals later published a Proof Pack, which included confidential information on a small number of patients, and warned more would follow. According to reports, more than 1TB of sensitive data has been made available, with the threat of a  further 3TB of data  to be made available.

The attack on NHS Scotland has been claimed by the Inc Ransomware collective on its dark web leak site. The attack is understood to have originally been conducted in March 2024, with the victim listed on the leak site shortly afterwards, and data made available for download in May 2024.  

Dark Web sites are not accessible by traditional search engines and browsers, meaning this goldmine of data is often missed by traditional security tools.

In comment, Lewis Shields, Director, Dark Ops at ZeroFox said "When compromised by digital extortion collectives, the first indication a victim organisation receives is often a ransom note from the threat actor, explaining that sensitive information, such as leaked or stolen data, compromised or breached credentials, intellectual property, and other sensitive materials, has been acquired and will be made available for illicit sale, should subsequent instructions not be followed... Once named on an extortion collective’s shame site, news of the attack makes its way to the surface Web and is made accessible to the general public, leaving compromised organisations to scramble for a plan to mitigate the operational, financial, and reputational damage that comes with an uncontained security incident." Shields observed.

ZeroFox advises that healthcare providers, along with other vulnerable organisations,  engage in monitoring criminal forums on the Dark Web, enabling them to better understand their external attack surface and stay ahead of the evolving cyber threat landscape. “Implementing a comprehensive Dark Web monitoring will extend the reach of an organisation’s security team to give them greater insight into emerging threats and hopefully, stop them before they become a problem.” according to Shields.

Keiron Holyome, VP UKI & Emerging Markets at BlackBerry said “This latest attack on the NHS, at Dumfries and Galloway in Scotland, highlights that threat actors can use any poorly-protected endpoint to enter and cripple a system... Sensitive NHS data has high value, and risks being held to ransom, released to the Dark Web, or sold to the highest bidder".

 BlackBerry’s latest quarterly intelligence report found that 62% of attacks targeted critical industries, including healthcare, exploiting security misconfigurations or unprotected legacy systems.

“To prevent attacks, healthcare organisations must ensure that cybersecurity protection covers every endpoint, from mobile devices to IoT-connected medical tools such as ventilators or robotic surgery equipment, equally comprehensively... Many departments will be running outdated, possibly unsupported, technologies, some systems may run offline or with infrequent connectivity - everything requires the same high level of protection to defend against the daily onslaught of attacks." Holyome commented.

In a statement, NHS Dumfries and Galloway confirmed that a "large volume of data" had been published in what iy described as an "utterly abhorrent criminal act". Work is beginning to take place with partner agencies to assess the data which has been published and  Police Scotland, the National Cyber Security Centre and the Scottish government are engaged in responding to the situation.

NHS Dumfries and Galloway is urging the public to be alert for any attempts to access their work and personal data and has warned people to be vigilant about any potential approach by someone claiming to be in possession of either their personal data or NHS data - whether this approach comes by email, telephone, social media or other means.

Potential victims are advised to take down details about the approach and contact Police Scotland and there is a dedicated NHS webpage set up in response to the cyber attack, with a helpline available on 01387 216 777.

Police Scotland said its "inquiries are continuing into a cyber attack on NHS Dumfries and Galloway".

ZeroFox   |   Blackberry   |   Sky   |

Image: 

You Might Also Read: 

Healthcare Has Issues With Outsourced Cyber Security:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible




 

« Mobile Gambling - Sportsbooks Face Growing Fraud
Dell Hacked - 49m Customers Exposed  »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

NextLabs

NextLabs

NextLabs provides data-centric security software to protect business-critical data and applications.

Telesoft Technologies

Telesoft Technologies

Telesoft Technologies is a global provider of cyber security, telecom and government infrastructure products and services.

Protergo Cyber Security

Protergo Cyber Security

Protergo Cyber Security is the first integrated provider of cybersecurity solutions in Indonesia. We proactively protect our clients from cyber threats.

Kymatio

Kymatio

Kymatio are pioneers in Artificial Intelligence applied to adaptive staff strengthening, cultural change and predictive internal risk analysis.

Eskive

Eskive

Eskive is a Brazilian cyber security awareness and education platform that empowers users and strengthens their company in the face of cyber threats.

Ingenio Global

Ingenio Global

Ingenio is a specialist recruitment business for SaaS companies. Our purpose is to source exceptional talent in areas including cyber security for leading SaaS companies in the UK and Ireland.

ProofID

ProofID

ProofID is a specialist provider of Identity Access Management (IAM) solutions. We focus on the solving the complex needs of the modern enterprise.

Content+Cloud

Content+Cloud

Content+Cloud is a leading technology services business and Managed Services Provider (MSP) with a genuine passion for helping your organisation to succeed, whatever your ambitions.

R-Tech

R-Tech

R-Tech GmbH manages the digital start-up initiative, whose goal is to build a sustainable start-up culture in the field of digitization throughout the Upper Palatinate district of Bavaria.

Ciphertex Data Security

Ciphertex Data Security

Ciphertex is a leading data security company that specializes in portable data encryption and privacy protection storage systems.

Netgo

Netgo

Netgo group meet the requirements of a complex, digitized world with IT consulting, IT solutions & services, managed & cloud services and software products & development.

Maintel

Maintel

Maintel provides cloud and managed communications services. We help our customers to deliver exceptional customer experiences, and to securely access their applications and their data.

Druva

Druva

Druva is the industry’s leading SaaS platform for data resiliency, and the only vendor to ensure data protection across the most common data risks backed by a $10m guarantee.

CommandK

CommandK

CommandK provides companies with infrastructure to protect their sensitive data. Built-in solutions to prevent data-leaks and simplify governance.

Datapac

Datapac

Datapac is one of Ireland’s largest and most successful ICT solutions and services providers. We have been at the forefront of technology innovation in Ireland for the past three decades.

Standard Notes

Standard Notes

Standard Notes is a secure digital notes app that protects your notes and files with audited, industry-leading end-to-end encryption.