The computer systems at Universal Health Services, which runs approximately 400 hospitals and care centres across the United States and the United Kingdom, recently experienced a massive ransomware attack, making it one of the largest medical cyberattacks in US history.
The number of ransomware attacks has grown significantly over the past few months, as cybercriminals look to cash in on security vulnerabilities emerging as a result of increased remote work practices.
The golden age of ransomware attacks
In early April, near the start of the global pandemic, INTERPOL warned that it had detected a significant increase in ransomware attacks against hospitals and medical services engaged in the virus response.
The following month, Fresenius, Europe’s largest private hospital operator that employs nearly 300,000 people across more than 100 countries, was hit with a ransomware attack on its technology systems. Hackers reportedly utilized the Snake ransomware to attack Fresenius. In September, police in Germany launched a homicide investigation after the death of a woman who was transferred to another hospital following a ransomware attack.
Meanwhile, the World Health Organization (WHO) revealed that it was experiencing double the usual number of cyberattacks against its systems, including hackers running malicious sites impersonating the WHO’s internal email system.
Ransomware is a type of malicious software that spreads across computer networks, encrypting files and demanding payment for a key to decrypt them. It’s become a common tactic for hackers, though attacks of this scale against medical facilities aren’t common.
“Not only has the number of ransomware attacks increased, but ransomware itself has evolved, with some of the most popular forms disappearing and new forms emerging. In some cases, these are even more disruptive and damaging,” says Juta Gurinaviciute, Chief Technology Officer at NordVPN Teams.
Putting patients’ safety at risk
A computer virus could put people in serious danger if the target is a healthcare facility. Experts say old machines and outdated software at hospitals have contributed to the spread of ransomware. If the situation doesn’t improve, it could put patients’ safety into further jeopardy.
“The consequences can be grave. If an attack happens in the middle of a surgery, whatever machines are being used could go down, forcing medical staff to fall back on manual methods,” comments the NordVPN Teams expert. ‘“MRI machines, ventilators, and some types of microscopes — are computers too. Just like our laptops, those computers come with software that the developers have to support. When the machines become old and outdated, the people who made them might stop supporting them. That means that old software can become vulnerable to attacks.”
In many cases, hackers threaten to leak the data they’ve stolen if the victim doesn’t pay a ransom — something that might strike fear and pressure victims to give into the extortion demands.
Patient records can sell for up to $1,000 on the black market due to the amount of information found in the documents, including date of birth, credit card information, Social Security number, address and email. Social Security numbers can be purchased for as little as $1, and credit card information sells for up to $110.
Therefore, there should be a two-pronged approach — one that allows the organization to protect everything and also achieve HIPAA compliance. Attacks don’t just expose data, but also open the organization up to HIPAA and GDPR violations and fines, according to a global research and advisory firm Gartner.
As governments around the world attempt to address the public health crisis and contain the spread of COVID-19, there’s a big chance that criminals will continue to exploit this chaos, triggering subsequent spikes in cyberattacks against healthcare institutions. According to Ms. Gurinaviciute, healthcare organizations, especially those that run outdated technology, should expect these kinds of attacks to continue happening around the globe.
7 steps to protect organization’s data
Cybersecurity doesn’t concern large hospitals or medical institutions exclusively, and general precautions should be taken in the medical industry regardless of institution size. NordVPN Teams experts suggest starting with the following:
- Updates. Ensuring security patches are applied as soon as possible helps prevent hackers from exploiting known vulnerabilities that help them gain a foothold in the network.
- Multi-factor authentication. Multi-factor authentication across the ecosystem can prevent hackers from moving across the network and gaining additional controls.
- Regular backups. Organizations should also regularly back up their systems, as well as test those backups on a regular basis as part of a recovery plan. If the worst happens and ransomware does infiltrate the network, there’s a known method of restoring it without the need to pay ransom to cybercriminals.
- Audits. Hospitals should conduct regular audits of their machines and segment their networks, so if one piece of the network is compromised, it doesn’t spread throughout the entire system.
- Remote access. Only secure virtual private network (VPN) connectivity should be allowed for remote access. In addition, only whitelisted IP addresses or device IDs should be allowed to access systems, as this will allow access to authorized users only.
- Treat every email with zero trust. Because of the remote work environment, the amount of information exchanged over the internet through virtual conferences and emails has skyrocketed. Establish a process that enables employees to report anything suspicious, and share regular updates and information about phishing emails.
- Security training. General security policies need to be drawn up and implemented, and staff have to be appropriately trained ad-hoc, whether remotely or in person.
For more information visit: nordvpnteams.com
For more Technology & Business news follow i-invest Online.
- Ark and Nebius collaborate to drive UK expansion of AI infrastructureHigh-density facility supports Nebius’s deployment of thousands of NVIDIA Blackwell Ultra GPUs and forms part of Ark’s £7.5 billion UK expansion roadmap Ark Data Centres, the UK’s leading data centre developer and operator, has announced a long-term agreement with Nebius (NASDAQ: NBIS), a leading AI infrastructure company, that will see one of the UK’s first… Read more: Ark and Nebius collaborate to drive UK expansion of AI infrastructure
- Unlock your ESG strategy with modern data architectureAgainst a backdrop of new legal requirements, such as the EU Taxonomy, modern data architecture holds the key to a sustainable supply chain transformation, says Tim Srock, CEO of Lobster In recent years, companies have been facing growing pressure to implement sustainable business practices transparently and efficiently. This is now expected of data management. The… Read more: Unlock your ESG strategy with modern data architecture
- Solve the AI sustainability conundrum and maximise operational efficiencyFrom streamlining ESG processes, to consuming vast amounts of energy, AI provides both opportunities and threats to the sustainability of industry. Julia Binder and José Parra Moyano of IMD unpack the issues Artificial intelligence is both a game-changer and a potential liability for business sustainability. On one hand, it offers transformative opportunities, optimising energy use,… Read more: Solve the AI sustainability conundrum and maximise operational efficiency
- Period tracking apps promise convenience – but at what cost?New research raises a number of ethical concerns and suggests users of apps to track menstrual cycles should be cautious Apps used to track menstrual cycles, monitoring periods and fertility windows are not as reliable as users may think they are, according to new research from Rotterdam School of Management Erasmus University (RSM). Such services,… Read more: Period tracking apps promise convenience – but at what cost?
- Harness a new world of opportunity powered by Tech for GoodThose who embrace innovation today will shape the markets of tomorrow, building a future where efficiency, transparency, and purpose go hand in hand, says thought-leader Marga Hoek A new era of innovation is redefining sustainability, offering an unprecedented opportunity to tackle climate change, biodiversity loss, inequality, poverty, and global health challenges. As detailed in my… Read more: Harness a new world of opportunity powered by Tech for Good