Stolen NHS Data Published On The Dark Web

A ransomware group has carried out its threat against a Scottish health board and published a "large volume" of stolen data on the Dark Web. NHS Dumfries and Galloway was hit by a cyber attack in March and confirmed hackers were able to access a "significant quantity of data", including patient and staff-identifiable information.

The cyber criminals later published a Proof Pack, which included confidential information on a small number of patients, and warned more would follow. According to reports, more than 1TB of sensitive data has been made available, with the threat of a  further 3TB of data  to be made available.

The attack on NHS Scotland has been claimed by the Inc Ransomware collective on its dark web leak site. The attack is understood to have originally been conducted in March 2024, with the victim listed on the leak site shortly afterwards, and data made available for download in May 2024.  

Dark Web sites are not accessible by traditional search engines and browsers, meaning this goldmine of data is often missed by traditional security tools.

In comment, Lewis Shields, Director, Dark Ops at ZeroFox said "When compromised by digital extortion collectives, the first indication a victim organisation receives is often a ransom note from the threat actor, explaining that sensitive information, such as leaked or stolen data, compromised or breached credentials, intellectual property, and other sensitive materials, has been acquired and will be made available for illicit sale, should subsequent instructions not be followed... Once named on an extortion collective’s shame site, news of the attack makes its way to the surface Web and is made accessible to the general public, leaving compromised organisations to scramble for a plan to mitigate the operational, financial, and reputational damage that comes with an uncontained security incident." Shields observed.

ZeroFox advises that healthcare providers, along with other vulnerable organisations,  engage in monitoring criminal forums on the Dark Web, enabling them to better understand their external attack surface and stay ahead of the evolving cyber threat landscape. “Implementing a comprehensive Dark Web monitoring will extend the reach of an organisation’s security team to give them greater insight into emerging threats and hopefully, stop them before they become a problem.” according to Shields.

Keiron Holyome, VP UKI & Emerging Markets at BlackBerry said “This latest attack on the NHS, at Dumfries and Galloway in Scotland, highlights that threat actors can use any poorly-protected endpoint to enter and cripple a system... Sensitive NHS data has high value, and risks being held to ransom, released to the Dark Web, or sold to the highest bidder".

 BlackBerry’s latest quarterly intelligence report found that 62% of attacks targeted critical industries, including healthcare, exploiting security misconfigurations or unprotected legacy systems.

“To prevent attacks, healthcare organisations must ensure that cybersecurity protection covers every endpoint, from mobile devices to IoT-connected medical tools such as ventilators or robotic surgery equipment, equally comprehensively... Many departments will be running outdated, possibly unsupported, technologies, some systems may run offline or with infrequent connectivity - everything requires the same high level of protection to defend against the daily onslaught of attacks." Holyome commented.

In a statement, NHS Dumfries and Galloway confirmed that a "large volume of data" had been published in what iy described as an "utterly abhorrent criminal act". Work is beginning to take place with partner agencies to assess the data which has been published and  Police Scotland, the National Cyber Security Centre and the Scottish government are engaged in responding to the situation.

NHS Dumfries and Galloway is urging the public to be alert for any attempts to access their work and personal data and has warned people to be vigilant about any potential approach by someone claiming to be in possession of either their personal data or NHS data - whether this approach comes by email, telephone, social media or other means.

Potential victims are advised to take down details about the approach and contact Police Scotland and there is a dedicated NHS webpage set up in response to the cyber attack, with a helpline available on 01387 216 777.

Police Scotland said its "inquiries are continuing into a cyber attack on NHS Dumfries and Galloway".

ZeroFox   |   Blackberry   |   Sky   |

Image: 

You Might Also Read: 

Healthcare Has Issues With Outsourced Cyber Security:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible




 

« Mobile Gambling - Sportsbooks Face Growing Fraud
Dell Hacked - 49m Customers Exposed  »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Code Dx

Code Dx

Code Dx is a software application vulnerability correlation and management system.

Quantivate

Quantivate

Quantivate is a provider of web-based Governance, Risk, and Compliance (GRC) software and service solutions.

Vade Secure

Vade Secure

Vade Secure provides protection against the most sophisticated email scams such as phishing and spear phishing, malware and ransomware.

Wind River

Wind River

Wind River delivers the technology and expertise that enables the deployment of safe, secure, and reliable intelligent connected systems.

bwtech@UMBC

bwtech@UMBC

The bwtech@UMBC Cyber Incubator is an innovative business incubation program that delivers business and technical support to start-up and early-stage cybersecurity/IT products and services companies.

GoCyber

GoCyber

GoCyber is a new, highly innovative cyber security training app that uses action based learning to significantly improve the online behaviour of all employees in less than a month.

DigiByte (DGB)

DigiByte (DGB)

DigiByte (DGB) is a rapidly growing global blockchain with a focus on cybersecurity for digital payments & decentralized applications.

Carve Systems

Carve Systems

Carve Systems was founded to bring enterprise level information security, training, and risk management services to organizations of any size and industry.

Cubro Network Visibility

Cubro Network Visibility

Cubro network visibility solutions remove network monitoring ‘blind spots’ to provide enhanced visibility and control of all data transiting a company’s network.

Upfront Security

Upfront Security

Upfront Security helps companies with innovative products & services to prevent, recognise and recover from (identity) fraud.

Cegeka

Cegeka

Cegeka is a family-owned IT company providing end-to-end IT solutions, services & consultancy.

Syracom

Syracom

syracom is a consultancy firm specialized in development of efficient business processes. With our expertise and IT competence, we develop tailored solutions for customers in various industries.

N2K Networks

N2K Networks

N2K Networks is the world’s first “news to knowledge” network. The news to knowledge network is how you stay at the cutting edge in a rapidly changing world.

Ruptura InfoSecurity

Ruptura InfoSecurity

Ruptura InfoSecurity provide CREST Accredited Penetration Testing & Offensive Security Services. We secure your critical assets through targeted and research driven penetration testing.

Netia

Netia

Netia is a Polish telecommunications company providing a range of business services including network solutions, communications, data centre and cloud, and cybersecurity.

System Two Security

System Two Security

System Two Security automates detection engineering and threat hunting.