Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

111–120 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#111
post #49
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

You could just have hospitals be required to meet FedRAMP compliance. It is kind of crazy that hipaa compliance isn’t encompassing enough

Likewise, I love FISMA, but I don't think hospitals would cease operations just because their systems couldn't get an ATO. What kind of accountability would motivate them to complete POAMs with any urgency? I don't think there is an effective way to incentivize a proactive approach - financial penalties would simply be indirectly paid for by customers.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#112
post #77
post #75

If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgat…

If US citizens die due to this, I am 100% down with bringing the full might of our military down on the state/group that did this. No mercy.

And how are you going to identify the state/group that did this? Believing "experts"? Oh, that worked just fine previously

https://en.wikipedia.org/wiki/United_Nations_Security_Counci...

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#113
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

If there's a zero day, there's not a lot you can do. NHS got hit so bad because they were running very old Windows versions. A lot of embedded systems have no upgrade paths (MRIs running embedded XP should probably not be on the network at all). Hospitals need full backup machines and with health care costs already through the roof, that will just add more. Even if you have all your order entry machines setup to not…

You're gonna need your MRIs on the network cuz they transmit the actual PHI via PACS.

No way the operator is copying a 5GB+ dicom file to your record in your EMR manually.

You NEED to have the patient name added via modality worklists to reduce errors (ie. add the pt to the MRI software before the scan, and send the scan to the EMR once it's taken).

The worst thing is, this protocol is old and insecure. They just don't have the IT chops at hospitals to handle this.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#115
post #8

This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.

>terrorism

Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#116
post #77

Earlier quoted context omitted.

If US citizens die due to this, I am 100% down with bringing the full might of our military down on the state/group that did this. No mercy.

The problem with this is that other bad players within US can "hack" this attempt to blame a state/group that had nothing to do with this. Has happened in the past.

Of course; it happens all the time. False flags (in the form of routed connections and much more) are extremely common in cyberwar and among cybercriminals, naturally. But can you name a time US law enforcement or military fucked up and fell for a "cyber false flag" [1], and mistakenly took action against the framed party? It may have happened, and I wouldn't be shocked, but I haven't actually seen a publicized case of it.

From having some knowledge of some investigations like these (though not on behalf of any government), the investigators and forensics experts are constantly asking themselves "is this a false flag? is this piece of evidence deliberately planted, or an actual mistake?" Investigators obviously want to get the right people and not get the wrong people. And in the case of nation-states, they also have classified information they can use (like from NSA global spying, etc.).

[1] (I shudder at the term "cyber" as much as anyone else reading this, but that pretty much is the official term the government uses.)

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#117
post #8

This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.

>terrorism Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.

Terrorism is a buzzword that means "Person I don't like" now.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#118

Earlier quoted context omitted.

Why the assumption that its terrorist and not a state sanctioned attack?

If we're honest, it's neither. It's 1000% profit-orientated.

Well I hope they don't request bitcoin since the US recently made it illegal to make cryptocurrency ransomware payments:

https://www.coindesk.com/ban-all-ransomware-payments-bitcoin

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#119

Earlier quoted context omitted.

>terrorism Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.

Terrorism is a buzzword that means "Person I don't like" now.

I thought terrorism were those guys we're at war with?

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#120

Earlier quoted context omitted.

What about management? What about the sysadmins/developers that left a security hole somewhere? Are they held responsible in some way? It's unacceptable that this keeps happening. If you own a safe and it gets broken into every week, do you blame the safe cracker or who built the safe?

Sometimes analogies can be misleading. It's a lot harder to design a secure hospital IT apparatus than a safe. Also, in the event of a safe getting cracked, you'd likely have no recourse against the safe vendor. Safes are designed to present a firewall against tampering, but with sufficient physical access, no safe will stand for long. So your analogy fails two ways: one is that it trivializes the difficulty of the p…

> It's a lot harder to design a secure hospital IT apparatus than a safe.

Yeah I agree there.

I'm curious what the surface area could look like. What is the minimum a hospital could operate with? How locked down could things be? Anyone in healthcare care to comment?

Post reply on HN