Get 40% Off
👀 👁 🧿 All eyes on Biogen, up +4,56% after posting earnings. Our AI picked it in March 2024.
Which stocks will surge next?
Unlock AI-picked Stocks

Building wave of ransomware attacks strike U.S. hospitals

Published 10/28/2020, 05:38 PM
Updated 10/29/2020, 10:00 AM
© Reuters. An empty hallway is pictured in a hospital in Philadelphia , Pennsylvania,

By Christopher Bing and Joseph Menn

WASHINGTON/SAN FRANCISCO (Reuters) - Eastern European criminals are targeting dozens of U.S. hospitals with ransomware, and federal officials on Wednesday urged healthcare facilities to beef up preparations rapidly in case they are next.

The FBI is investigating the recent attacks, which include incidents in Oregon, California and New York made public just this week, according to three cybersecurity consultants familiar with the matter.

A doctor at one hospital told Reuters that the facility was functioning on paper after an attack and unable to transfer patients because the nearest alternative was an hour away. The doctor declined to be named because staff were not authorized to speak with reporters.

"We can still watch vitals and getting imaging done, but all results are being communicated via paper only," the doctor said. Staff could see historic records but not update those files.

Experts said the likely group behind the attacks was known as Wizard Spider or UNC 1878. They warned that such attacks can disrupt hospital operations and lead to loss of life.

The attacks prompted a teleconference call on Wednesday led by FBI and Homeland Security officials for hospital administrators and cybersecurity experts.

A participant told Reuters that government officials warned hospitals to make sure their backup systems were in order, disconnect systems from the internet where possible, and avoid using personal email accounts.

The FBI did not immediately respond to a request for comment.

“This appears to have been a coordinated attack designed to disrupt hospitals specifically all around the country,” said Allan Liska, a threat intelligence analyst with U.S. cybersecurity firm Recorded Future.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

“While multiple ransomware attacks against healthcare providers each week have been commonplace, this is the first time we have seen six hospitals targeted in the same day by the same ransomware actor.”

In the past, ransomware infections at hospitals have downed patient record-keeping databases, which critically store up-to-date medical information, affecting hospitals’ ability to provide healthcare.

Ransomware attacks have jumped 50% over the past three months, security firm Check Point (NASDAQ:CHKP) said Wednesday, with the proportion of polled healthcare organizations impacted jumping to 4% in the third quarter from 2.3% in the previous quarter.

Two of the three consultants familiar with the attacks said the cyber criminals were commonly using a type of ransomware known as “Ryuk,” which locks up a victim's computer until a payment is received.

The teleconference call participant said government officials disclosed that the attackers used Ryuk and another trojan, known as Trickbot, against the hospitals.

"UNC1878 is one of the most brazen, heartless, and disruptive threat actors I’ve observed over my career," said Charles Carmakal, senior vice president for U.S. cyber incident response firm Mandiant.

"Multiple hospitals have already been significantly impacted by Ryuk ransomware and their networks have been taken offline."

Experts say the deployment of Trickbot is significant after efforts by Microsoft (O:MSFT) to disrupt the hacking network earlier this month.

That initiative was designed to handicap the cyber criminals, but they seem to have recovered quickly, said Stefan Tanase, a cyber crime analyst.

"What we are seeing here is confirmation that the reports of the Trickbot takedown were greatly exaggerated," he said.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

Microsoft did not answer a request for comment.

Latest comments

They get what they deserve. Hospitals keep hiring uncompetent IT persons. The idea is any Indian is good at IT is appalling.
Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.