Stolen NHS Data Published On The Dark Web

A ransomware group has carried out its threat against a Scottish health board and published a "large volume" of stolen data on the Dark Web. NHS Dumfries and Galloway was hit by a cyber attack in March and confirmed hackers were able to access a "significant quantity of data", including patient and staff-identifiable information.

The cyber criminals later published a Proof Pack, which included confidential information on a small number of patients, and warned more would follow. According to reports, more than 1TB of sensitive data has been made available, with the threat of a  further 3TB of data  to be made available.

The attack on NHS Scotland has been claimed by the Inc Ransomware collective on its dark web leak site. The attack is understood to have originally been conducted in March 2024, with the victim listed on the leak site shortly afterwards, and data made available for download in May 2024.  

Dark Web sites are not accessible by traditional search engines and browsers, meaning this goldmine of data is often missed by traditional security tools.

In comment, Lewis Shields, Director, Dark Ops at ZeroFox said "When compromised by digital extortion collectives, the first indication a victim organisation receives is often a ransom note from the threat actor, explaining that sensitive information, such as leaked or stolen data, compromised or breached credentials, intellectual property, and other sensitive materials, has been acquired and will be made available for illicit sale, should subsequent instructions not be followed... Once named on an extortion collective’s shame site, news of the attack makes its way to the surface Web and is made accessible to the general public, leaving compromised organisations to scramble for a plan to mitigate the operational, financial, and reputational damage that comes with an uncontained security incident." Shields observed.

ZeroFox advises that healthcare providers, along with other vulnerable organisations,  engage in monitoring criminal forums on the Dark Web, enabling them to better understand their external attack surface and stay ahead of the evolving cyber threat landscape. “Implementing a comprehensive Dark Web monitoring will extend the reach of an organisation’s security team to give them greater insight into emerging threats and hopefully, stop them before they become a problem.” according to Shields.

Keiron Holyome, VP UKI & Emerging Markets at BlackBerry said “This latest attack on the NHS, at Dumfries and Galloway in Scotland, highlights that threat actors can use any poorly-protected endpoint to enter and cripple a system... Sensitive NHS data has high value, and risks being held to ransom, released to the Dark Web, or sold to the highest bidder".

 BlackBerry’s latest quarterly intelligence report found that 62% of attacks targeted critical industries, including healthcare, exploiting security misconfigurations or unprotected legacy systems.

“To prevent attacks, healthcare organisations must ensure that cybersecurity protection covers every endpoint, from mobile devices to IoT-connected medical tools such as ventilators or robotic surgery equipment, equally comprehensively... Many departments will be running outdated, possibly unsupported, technologies, some systems may run offline or with infrequent connectivity - everything requires the same high level of protection to defend against the daily onslaught of attacks." Holyome commented.

In a statement, NHS Dumfries and Galloway confirmed that a "large volume of data" had been published in what iy described as an "utterly abhorrent criminal act". Work is beginning to take place with partner agencies to assess the data which has been published and  Police Scotland, the National Cyber Security Centre and the Scottish government are engaged in responding to the situation.

NHS Dumfries and Galloway is urging the public to be alert for any attempts to access their work and personal data and has warned people to be vigilant about any potential approach by someone claiming to be in possession of either their personal data or NHS data - whether this approach comes by email, telephone, social media or other means.

Potential victims are advised to take down details about the approach and contact Police Scotland and there is a dedicated NHS webpage set up in response to the cyber attack, with a helpline available on 01387 216 777.

Police Scotland said its "inquiries are continuing into a cyber attack on NHS Dumfries and Galloway".

ZeroFox   |   Blackberry   |   Sky   |

Image: 

You Might Also Read: 

Healthcare Has Issues With Outsourced Cyber Security:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible




 

« Mobile Gambling - Sportsbooks Face Growing Fraud
Dell Hacked - 49m Customers Exposed  »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

FT Cyber Resilience Summit: Europe

FT Cyber Resilience Summit: Europe

27 November 2024 | In-Person & Digital | 22 Bishopsgate, London. Business leaders, Innovators & Experts address evolving cybersecurity risks.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Intercede

Intercede

Intercede is a cybersecurity company specializing in digital identities, derived credentials and access control, enabling digital trust in a mobile world.

ISACA Conferences

ISACA Conferences

ISACA is dedicated to offering the most dynamic and inclusive conferences to keep you abreast of the latest advances in IT and Information Security.

Jumpsec

Jumpsec

Jumpsec provides penetration testing, security assessments, social engineering testing, cyber incident response, training and consultancy services.

Lutech

Lutech

Lutech is an Italian ICT engineering and services company. Business solution areas include cyber security.

techUK

techUK

techUK represents companies operating in the tech sector in the UK. Focus areas cover all aspects of ICT including cyber security.

RKH Specialty

RKH Specialty

RKH Specialty, part of the Hyperion Insurance Group, is a provider of specialty insurance services including Cyber Risk cover.

National Cyber Security Centre (NCSC) - Ireland

National Cyber Security Centre (NCSC) - Ireland

The National Cyber Security Centre (NCSC) is the operational side of the Department of Communications in regard to network and information security in the Republic of Ireland.

A-LIGN

A-LIGN

A-LIGN is a technology-enabled security and compliance partner trusted by more than 2,500 global organizations to mitigate cybersecurity risks.

LUCY Security

LUCY Security

LUCY is the answer when you want to increase your IT security, maintain your cyber security awareness, or test your IT defenses.

Crypto Quantique

Crypto Quantique

Crypto Quantique's ground-breaking technology radically simplifies the process of generating a hardware root of trust in an IoT device.

Bitcrack

Bitcrack

Bitcrack Cyber Security helps your company understand and defend your threat landscape using our key experience and skills in cybersecurity, threat mitigation and risk.

PreEmptive Solutions

PreEmptive Solutions

PreEmptive Protection hit the sweet spot between cost, convenience and functionality by helping you protect and secure your apps in a smarter way.

Samurai Digital Consulting

Samurai Digital Consulting

Samurai Digital Security are a cyber and Information security services provider, specialising in penetration testing, incident response, user awareness and information governance solutions.

Anterix

Anterix

Anterix is focused on empowering the modernization of critical infrastructure and enterprise businesses by enabling private broadband connectivity.

NetGain Technologies

NetGain Technologies

NetGain Technologies helps small to medium-sized businesses gain access to expert IT talent. We provide strategies that use technology as a driving force behind business growth.

Snare

Snare

Snare is a comprehensive set of event monitoring and analysis tools designed to address critical auditing and security requirements.