Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

351–357 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#351
post #288

Earlier quoted context omitted.

Attacking a hospital is a war crime, so how is it not terrorism?

One involves the violent deaths of hundreds or thousands of innocent civilians. The other involves financial loss and probably a temporary shut-down of one or more hospitals. Frankly, a cyberattack is the kind of thing a hospital can and should be hardened against. This is an administrative and regulatory failure being dressed up as "terrorism." Criminals that use ransomware should be prosecuted and sent to prison, n…

While I agree hospitals should have protocols to handle these situations, it's just not that straight forward. These IT systems are big and complex, and not standardized.

I worked on critical systems in the energy sector and while we were buried in federal compliance paperwork, the systems and software were always a target that was evolving and hard to keep up with. The energy management system was a huge bureaucratic battle between IT and engineering and there were compromises made (that I didn't always agree with) for the sake of support and maintainability within the IT tech landscape. For compliance reasons, and because the system is "offline", upgrades and patches were really challenging and honestly kind of terrifying. The risk of taking something down and impacting grid operations was harrowing. It really made our small team reticent to touch anything. I don't envy these hospitals, it's a really tough battle to ensure your systems are always up to date, locked down, and operational.

Also, a hospital going down is not a small problem. My wife is an ICU doctor for a large hospital and her patients' are sometimes hanging on by a thread. If they lost their EHR and patient history, I imagine that would present a really scary challenge. It's not just financial.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#352
The actors responsable are doing an all out attack to maximize profits as US Large corps and military are currently targeting their networks to prevent election tampering. These botnet networks have prooven difficult to disrupt even fort hem. This is a profit maximization effort for them and probably one they'll do right before folding and disappearing as the last time hosptials and police were directly targeted national governments began disappearing the perpitrators.

What'd be heartless is if the malware, such as the ryuk ransomware in December of 2019, had a bug in it that prevented the decryption key from working and all it did was garble and trash data.

Be forwarned, a few groups deploying ransomware are on sanctions lists which carries direct liability if you pay them. If you're the IT staff, make the CFO\CEO pay them and wash your hands of it.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#353
post #8

This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.

The hospital chain I work for was hit with ransomware last month. Door locks, time clocks, and photocopy machines still worked, but all computers were down. We use paper records, but it was frustrating and inconvenient. We're not allowed to pay due to laws. Corporate started slowly building us a brand new, but terrible, network 5 weeks after the old one went down. Definitely caused a little staff burnout, but not mor…

If they treat you like an ATM machine, you treat them as such. 40 hr weeks, go home, and DGAF.

Patients dieing because people don't work 80hr weeks? Why are you working for such a shit management team? That's management's problem. Don't like it? Quit. Really don't like it? Name and shame.

It's unfortunate we live in a day and age that kind of thinking is necissary but it is. Burnout in the middle of a pandemic can get you killed.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#354

Earlier quoted context omitted.

It also means that the easiest way to earn more profit is for healthcare costs (the 80%) to be higher. Kind of a perverse incentive in the long run.

Only if the insurance companies form a cartel (in the economic sense). People will switch carriers to ones with lower premiums so the market forces direct costs down to parity. Most costs are outside of insurer's control anyway, regulations prevent insurance companies from telling providers how to offer care as long as the care is medically necessary and the standard of care.

While it's true that a cartel would be the fastest way to raise prices, I don't think that not having one removes all incentive to try.

I think you're also ignoring healthcare networks. This is important for two reasons.

1. The kind of supply and demand works very well for modeling commodities, but the difference in networks means it's very hard to have two completely equivalent insurance products.

2. Insurance companies can incentivize hospitals to behave in certain ways by regularly pruning those who do not behave that way.

Also, most people get their healthcare from their employer. There's not as much ability to actually switch, unless you're so fed up that you're willing to switch jobs.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#355
post #202

Earlier quoted context omitted.

This. A million times. Regulation isn't the solution to this industry's woes -- it's the cause.

I am pretty sure patients outcomes would be much better with no regulation at all. Be careful what you wish for. Many regulations have been written in blood.

Ha! Sorry, my political views are non-binary so I see how you're confused. Allow me to clarify: the regulations in the health care industry are structured poorly and have strong disincentives to even the simplest and most obvious improvements (e.g. updating software to receive security updates). They should not be removed, but they need to be rethought so people in the industry aren't afraid to make changes.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#356

Is there an analysis of the stack (OS, apps) used by victim orgs and the holes in their systems? I'm guessing its always EOLed Windows versions.

it is definitely not always eol windows, most ransomware I have seen rune on modern os, fully patched with you to date av. it is not hard to creat or distribute or to mutate and keep active. it is not just windows either, I have seen it for osx and ubuntu, even cloud services like office365, Dropbox, etc.

99% of the time the hole in the system is the phishing email that the employee clicks on. you will be amazed how many link clicks, redirects warning messages and notices people will just click through because "hr" needs to verify you payroll information or other nonsense that doesn't even make sense.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#357

Earlier quoted context omitted.

I think the obvious solution would be to invest in a new open-source end-to-end infrastructure that could be thoroughly audited then implemented by hospitals everywhere. Of course, that would need a sizeable investment of both money and time, but it would almost definitely be more efficient than updating one component at a time.

My armchair analysis of the obvious solution is to airgap all these systems. Perhaps this would require some new infrastructure in hospitals, but it would add a very difficult-to-penetrate layer.

Hospitals are porous, almost public places. You need EMR terminals in rooms where patients are left alone with the door closed overnight.
Post reply on HN