Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

161–170 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#161
post #83

Earlier quoted context omitted.

Health insurance premiums are just total healthcare costs for the insured lives plus x% for operations of the health insurance company. If all hospitals have to raise prices to meet IT costs, then presumably the total cost of healthcare for the insured lives goes up, and hence the health insurance premium has to go up. So yes, typically if your vendor's suppliers increase price, then your vendor will increase their p…

> health insurance is already a low margin business I’d like to know much, much more about this statement.

It’s public information, check any of the big health insurers’ 10-K and it’s probably less than 5%.

https://naic.org/documents/topic_insurance_industry_snapshot...

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#162
post #8

This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.

>terrorism Isn't ransomware profit-motivated? I thought with terrorism the goal was fear rather than profit.

We can easily reconcile the two by recognizing that profit doesn't have to be money and that terrorists definitely profit from fear (otherwise they wouldn't do it). Everything we do is for profit, even if that profit isn't measured exclusively in dollars.

We can further reconcile them by saying that the entire mechanism for extracting money from the ransom victim is by making them afraid. In this case, afraid of losing their computer systems.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#163
post #104

Earlier quoted context omitted.

By the ACA law health insurance companies have to pay out at least 80% of premiums on claims. The cost of running the company and any profit has to come out of the other 20%. 5% of billions of dollars is huge in absolute figures but as a percentage falls in line with other industries.

This sounds like an incentive to increase costs (20% of 2X > 20% of X).

Assuming no competitor exist, which they do for many health insurance situations. There would be plenty of competitors to choose from if everyone was required to choose from healthcare.gov.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#164

Earlier quoted context omitted.

Of course; it happens all the time. False flags (in the form of routed connections and much more) are extremely common in cyberwar and among cybercriminals, naturally. But can you name a time US law enforcement or military fucked up and fell for a "cyber false flag" [1], and mistakenly took action against the framed party? It may have happened, and I wouldn't be shocked, but I haven't actually seen a publicized case…

> But can you name a time US law enforcement or military fucked up and fell for a "cyber false flag" SWATting via VoIP spoofing etc., could arguably fall entirely within the realm of this.

True, that's one key example. I should've clarified that I'm referring to arrests, prosecution, and imprisonment. Also, such hoaxes (and things like bomb threat hoaxes) did still happen before the popularity of the internet; they can be done from a payphone, for example. The internet definitely makes it a lot easier, though.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#166
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

The regulatory environment in the Heath Care industry is based on the premise that any change risks patient safety. Changing a single line of CSS literally takes 6 months to test, validate, document and get approval for, so everyone's afraid to change a thing. You can't automate anything because the current process survived 7 audits and regulatory is afraid changing it might raise an alarm. You'd be stunned at the number of hospitals still running Windows XP. Most systems use a plain text messaging protocol designed in the 80's -- no encryption or authentication anywhere to be seen, and half of them write messages to disk because "it's safer". If ever there was an example of well intentioned regulation gone horribly wrong this is it. The whole industry is a cyber security nightmare waiting to happen.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#167
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

In general, regulated entities are required to regularly prove that their change-management processes are sufficiently heavy as to make regular patching a non-starter.

This. A million times. Regulation isn't the solution to this industry's woes -- it's the cause.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#168
post #38

Earlier quoted context omitted.

My hospital offline for a whole week because they got hit by a ransomware attack, and they use Epic. I asked someone I knew at Epic what she knew about it, and confirmed that my hospital was up-to-date on the latest version of their software and following most of their security protocols. My initial thought was they had weak IT security and now I’m not so sure.

Doesn’t matter if their Epic servers are up to date if the attacker got a domain admin account somewhere else and can just log in normally to run the ransomware.

Yup just spearfish one of the employees with a password reset email. People including educated developers and MDs are in general very lax about security. But also you have windows 7 legacy systems running specialized equipment that has been validated for that OS and software version number. There is really no way around this, if a country wants to kill Americans right now IMO it is most effective to disable EPIC servers in ND/SD/WI/MT that would cause way too much chaos and people would die.

But also what are we doing running life-critical software on Microsoft-made OS? This is idiotic, it is great for gaming and excel but not hospitals. Microsoft could make another OS based on Linux or BSD and it could not be hot garbage. But that would eat into profits and take...effort. Linux and ChromeOS + 2FA is much better although not perfect.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#169

Earlier quoted context omitted.

You gotta wait for it to be declassified. Syria was likely CIA funded. Same with Libya. Just wait a bit. It all comes out after everyone's stopped caring.

Are you speaking about Syria and Libya today that was a result of the Arab Spring in multiple Arab countries, which took everyone including CIA by surprise? Do you really believe the CIA is capable of something on that scale? https://en.wikipedia.org/wiki/Arab_Spring

If it took the CIA by surprise, why were Syria and Libya on the short list of countries that General Wesley Clark identified as regime change targets in 2007, three years before the Arab Spring?

https://youtu.be/9RC1Mepk_Sw

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#170

Earlier quoted context omitted.

You gotta wait for it to be declassified. Syria was likely CIA funded. Same with Libya. Just wait a bit. It all comes out after everyone's stopped caring.

Are you speaking about Syria and Libya today that was a result of the Arab Spring in multiple Arab countries, which took everyone including CIA by surprise? Do you really believe the CIA is capable of something on that scale? https://en.wikipedia.org/wiki/Arab_Spring

There have been many parties involved in both Syria and Libya. Just take the NATO involvement in Libya for example:

https://en.wikipedia.org/wiki/2011_military_intervention_in_...

Syria is just as complicated if not more so. It turned into a proxy war between the US and Russia and don't forget ISIS and the many different factions who have received funding from multiple sources.

How many people have been killed in the US this year causing and because of the protests at the hands of government and extremists? I don't think we'll be getting a NATO bombing anytime soon. I also can't picture that happening in Nigeria.

Post reply on HN