Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

31–40 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#31
post #12

That's messed up if true, but why would a ransomware operator target them? I mean like, they don't really target, they just wait for people to install something right?

Probably for initial infection it’s random but the negotiation for keys happens between real people. Thieves must be heartless to go after such desperate targets. But criminals always have ways of justifying things.

> Thieves must be heartless to go after such desperate targets.

I mean it's the mafia, same people that traffic women and children, drugs,... profit is the motive, they don't care how. Just because they are now sitting behind a computer doesn't change their nature.

I've been in a hospital recently and they were still running windows XP, my doctor using IE8 (cause activeX on the intranet) and Excel... But hey, they run anti-viruses!... Public institutions absolutely need to get rid of all that ASAP.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#32
post #8

This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.

Does anyone else feel that any organization that isn't doing regular secure backups with a way to restore that data deserves for this to happen? It like an airplane running out of gas because the pilot forgot to fill up the tank. Its kind of step one of working with computers.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#33
post #21

Earlier quoted context omitted.

Ransomware shops don't sit passively by, waiting for someone to install a trojan. Some of them are actually outsourcing the actual penetration, according to Krebs: https://krebsonsecurity.com/2020/10/amid-an-embarrassment-of... And once you're doing that, you're going to minimax for hi-value, low-risk targets.

Or the leaders of these "shops" have a variety of national politicians as clients.

the only reason that's unlikely is because the effort behind this level of conspiracy is just so unnecessary to having a viable business plan

its like yeaaah maaaybe there is one connected and high tech operation that all the world leaders heard about in their whatsapp groups, but my experience with "people with connections" are that they are so low tech and dumb that its almost impossible for them to get the correct clandestine hacker group in play

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#34
post #8

This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.

Does anyone else feel that any organization that isn't doing regular secure backups with a way to restore that data deserves for this to happen? It like an airplane running out of gas because the pilot forgot to fill up the tank. Its kind of step one of working with computers.

“Deserve” doesn’t do anything for the people hurt by this, and it doesn’t justify the behavior of the hackers.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#35
post #8

This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.

Why the assumption that its terrorist and not a state sanctioned attack?

These are not mutually exclusive.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#36

That's messed up if true, but why would a ransomware operator target them? I mean like, they don't really target, they just wait for people to install something right?

Why hospitals? They have lots of money (same as any big organization) and a very good reason to pay up. It would be far from the first time a hospital was attacked. It wouldn't even by the first time it directly resulted in a death [0]. Unfortunately ransomware operators aren't very ethical. Considering the timing it could also be geopolitical unfortunately, people dying from a ransomware attack could substantially r…

I'm not experiencing any surprise that the hospitals are attacked, I know that happens, I am experiencing surprise at three government agencies hanging out in a chatroom where hackers are credibly discussing attacking a bunch of hospitals with ransomware.

My understanding is that the ransomware operators just take a look at computers that are infected, and then negotiate based on who they appear to be.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#38
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

My hospital offline for a whole week because they got hit by a ransomware attack, and they use Epic. I asked someone I knew at Epic what she knew about it, and confirmed that my hospital was up-to-date on the latest version of their software and following most of their security protocols. My initial thought was they had weak IT security and now I’m not so sure.

Doesn’t matter if their Epic servers are up to date if the attacker got a domain admin account somewhere else and can just log in normally to run the ransomware.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#40

That's messed up if true, but why would a ransomware operator target them? I mean like, they don't really target, they just wait for people to install something right?

While the initial infection of a single workstation is often done by pray-and-spray phishing attacks, the common practice for modern ransomware attacks is that this is followed by a manually controlled attack by skilled teams, spreading throughout the network and servers is not done by an automated virus, it's done by controlled malware; and the encryption is manually triggered when they think that the preparations are complete to do maximum damage, backups have been disabled/corrupted, etc.

So they do target the extortion; already the decision to move on from that initial foothold will be based on the understanding of what institution it is and how much they would be willing to pay. In this case, they have intentionally targeted hospitals.

Post reply on HN