Stolen NHS Data Published On The Dark Web

A ransomware group has carried out its threat against a Scottish health board and published a "large volume" of stolen data on the Dark Web. NHS Dumfries and Galloway was hit by a cyber attack in March and confirmed hackers were able to access a "significant quantity of data", including patient and staff-identifiable information.

The cyber criminals later published a Proof Pack, which included confidential information on a small number of patients, and warned more would follow. According to reports, more than 1TB of sensitive data has been made available, with the threat of a  further 3TB of data  to be made available.

The attack on NHS Scotland has been claimed by the Inc Ransomware collective on its dark web leak site. The attack is understood to have originally been conducted in March 2024, with the victim listed on the leak site shortly afterwards, and data made available for download in May 2024.  

Dark Web sites are not accessible by traditional search engines and browsers, meaning this goldmine of data is often missed by traditional security tools.

In comment, Lewis Shields, Director, Dark Ops at ZeroFox said "When compromised by digital extortion collectives, the first indication a victim organisation receives is often a ransom note from the threat actor, explaining that sensitive information, such as leaked or stolen data, compromised or breached credentials, intellectual property, and other sensitive materials, has been acquired and will be made available for illicit sale, should subsequent instructions not be followed... Once named on an extortion collective’s shame site, news of the attack makes its way to the surface Web and is made accessible to the general public, leaving compromised organisations to scramble for a plan to mitigate the operational, financial, and reputational damage that comes with an uncontained security incident." Shields observed.

ZeroFox advises that healthcare providers, along with other vulnerable organisations,  engage in monitoring criminal forums on the Dark Web, enabling them to better understand their external attack surface and stay ahead of the evolving cyber threat landscape. “Implementing a comprehensive Dark Web monitoring will extend the reach of an organisation’s security team to give them greater insight into emerging threats and hopefully, stop them before they become a problem.” according to Shields.

Keiron Holyome, VP UKI & Emerging Markets at BlackBerry said “This latest attack on the NHS, at Dumfries and Galloway in Scotland, highlights that threat actors can use any poorly-protected endpoint to enter and cripple a system... Sensitive NHS data has high value, and risks being held to ransom, released to the Dark Web, or sold to the highest bidder".

 BlackBerry’s latest quarterly intelligence report found that 62% of attacks targeted critical industries, including healthcare, exploiting security misconfigurations or unprotected legacy systems.

“To prevent attacks, healthcare organisations must ensure that cybersecurity protection covers every endpoint, from mobile devices to IoT-connected medical tools such as ventilators or robotic surgery equipment, equally comprehensively... Many departments will be running outdated, possibly unsupported, technologies, some systems may run offline or with infrequent connectivity - everything requires the same high level of protection to defend against the daily onslaught of attacks." Holyome commented.

In a statement, NHS Dumfries and Galloway confirmed that a "large volume of data" had been published in what iy described as an "utterly abhorrent criminal act". Work is beginning to take place with partner agencies to assess the data which has been published and  Police Scotland, the National Cyber Security Centre and the Scottish government are engaged in responding to the situation.

NHS Dumfries and Galloway is urging the public to be alert for any attempts to access their work and personal data and has warned people to be vigilant about any potential approach by someone claiming to be in possession of either their personal data or NHS data - whether this approach comes by email, telephone, social media or other means.

Potential victims are advised to take down details about the approach and contact Police Scotland and there is a dedicated NHS webpage set up in response to the cyber attack, with a helpline available on 01387 216 777.

Police Scotland said its "inquiries are continuing into a cyber attack on NHS Dumfries and Galloway".

ZeroFox   |   Blackberry   |   Sky   |

Image: 

You Might Also Read: 

Healthcare Has Issues With Outsourced Cyber Security:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible




 

« Mobile Gambling - Sportsbooks Face Growing Fraud
Dell Hacked - 49m Customers Exposed  »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Cambray Solutions

Cambray Solutions

Cambray Solutions specializes in locating and securing technical professionals, managers, and executives.

RoboForm

RoboForm

RoboForm's industry-leading encryption technology securely stores your passwords, with one Master Password serving as your encryption key.

Cyber Security Experts Association of Nigeria (CSEAN)

Cyber Security Experts Association of Nigeria (CSEAN)

Cyber Security Experts Association of Nigeria (CSEAN) is a not for profit group of professionals in the field of Information Security in Nigeria and Diaspora.

Qolcom

Qolcom

Qolcom is a leading UK based integrator of secure wireless network and mobile device management solutions.

VADO Security Technologies

VADO Security Technologies

VADO Security enables the safe transfer of data between low & high security networks.

DefCamp

DefCamp

DefCamp is the most important annual conference on Hacking & Information Security in Central Eastern Europe.

Padlock

Padlock

Padlock is a trusted platform with an intimate knowledge of the cybersecurity industry that connects businesses with freelance professionals

Tenzir

Tenzir

Tenzir's primary focus lies on network forensics: the systematic investigation of cyber attacks with big data analytics.

Sternum

Sternum

Sternum provides reliable and effective endpoint security for any IoT device, using robust technology and seamless integration.

Exeon Analytics

Exeon Analytics

Exeon Analytics is a Swiss cyber security company that is specialized in detecting hidden data breaches and advanced cyber attacks.

First Point Group (FPG)

First Point Group (FPG)

First Point Group provide a global technological recruitment service worldwide. Within that we have a specialist team of Cyber Security recruiters.

Citalid

Citalid

The Citalid cyber risk management platform combines threat and business intelligence to identify the risks scenarios you face.

BATM Advanced Communications

BATM Advanced Communications

BATM Advanced Communications is a leading provider of real-time technologies for networking and cyber security solutions.

Schillings

Schillings

Shillings defends your rights to privacy, reuptation and security. We fight passionately against breaches of your privacy, attacks on your reputation and threats to your security.

aFFirmFirst

aFFirmFirst

aFFirmFirst is a unique software solution offering a simple yet effective way for businesses to protect and control their online images and logo, as well as allowing one-click website verification.

Lyvoc

Lyvoc

Lyvoc is a premier cybersecurity integration partner renowned for its expertise in supporting its clients to accelerate and secure their digital transformation.