Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

341–350 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#341

Earlier quoted context omitted.

Takes a goofy definition of terrorism to get Bay of Pigs to fit. A military attempt to overthrow a violent leader of another country doesn’t really land in the same category of shutting down hospitals and killing sick people with no political power.

Using violence to attempt to cause a regime change without formally declaring war, sounds much more like the traditional definition of terrorism to me [although maybe not the perfect fit], then randsomware which sounds like organized crime to me.

Sorry, to be clear. The definition of terrorism that most people are used to is the one that involves attacking people not anywhere in the government leadership hierarchy. For example, blowing up a commuter bus serves no purpose to take over a regime (unless the president was on that bus). The end goal is purely to cause fear.

Trying to quickly or quietly overthrow a government is pretty much the opposite of that effect. You want a quick change and the end goal is power, not fear for the sake of fear.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#342

Earlier quoted context omitted.

Using violence to attempt to cause a regime change without formally declaring war, sounds much more like the traditional definition of terrorism to me [although maybe not the perfect fit], then randsomware which sounds like organized crime to me.

Sorry, to be clear. The definition of terrorism that most people are used to is the one that involves attacking people not anywhere in the government leadership hierarchy. For example, blowing up a commuter bus serves no purpose to take over a regime (unless the president was on that bus). The end goal is purely to cause fear. Trying to quickly or quietly overthrow a government is pretty much the opposite of that eff…

Governments can fall if the people feel they aren't protected, although in practise that rarely happens. Groups like the FLQ, IRA, etc may have bombed civilian targets that really didn't have to do with the government, but they were still clearly aiming at political change.

Which groups do you think is fear for the sake of fear? Lots of groups are characterized that way for propaganda purposes, and deep down inside there are probably more than a few that just want the world to burn, but im not sure any exist that literally claim to just want to cause fear without tying it to some broader political goals.

> Trying to quickly or quietly overthrow a government is pretty much the opposite of that effect

I agree generally that quiet coups aren't generally in the terrorism category, but i still think they have much more in common with terrorism than (apolitical) ransomware does.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#343

Earlier quoted context omitted.

Why hospitals? They have lots of money (same as any big organization) and a very good reason to pay up. It would be far from the first time a hospital was attacked. It wouldn't even by the first time it directly resulted in a death [0]. Unfortunately ransomware operators aren't very ethical. Considering the timing it could also be geopolitical unfortunately, people dying from a ransomware attack could substantially r…

> It would be far from the first time a hospital was attacked. It wouldn't even by the first time it directly resulted in a death [0] Just pointing out that this is a little misleading. The link you're referencing refers to the first ever reported hospital death related to a hospital's ransomware attack, and this article was from just a month ago (I remember, I read it on Hacker News too). But the juxtaposition of th…

It was certainly not my intent to mislead with that, I apologize if it was less than clear.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#344

Earlier quoted context omitted.

NotPetya is a good example. Looked like a broad ransomware attack very similar to the earlier Petya attack. Turned out it was very likely a broad cover for a very narrow attack against Ukraine’s power grid during Russian invasion.

Say what you will about Russia, but I don't believe they'd attack hospitals dealing with COVID in the middle of the pandemic as a cover for some kind of attack. I know anti-Russia propaganda is at its height now and I even admit it's weird watching how worked up Americans get about stuff they're been doing all around the world since WWII, but as bad as Russia might be, I don't really buy they're behind it.

> Say what you will about Russia, but I don't believe they'd attack hospitals dealing with COVID in the middle of the pandemic as a cover for some kind of attack.

I wouldn't characterize it as an attack, its closer to "preparing an attack". And why not - the former President of the United States outright said on TV that the US had placed dormant implants deep inside key Russian infrastructure without pulling the trigger as a preparations/part of countermeasures for electoral meddling in 2016. The decision to pull the trigger was left as an option for his successor. I do not doubt the Russians may be getting similar "insurance" against a possible unfriendly posture from Washington starting January 2021.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#345
post #201

Earlier quoted context omitted.

If it's a fake ransomware then yeah that's probably terrorism. If it's fake it's obviously not done for profit. I'm referring to actual ransomware that works, that's done for profit. > On a more theoretical level, it's certainly possible to do both at the same time, two birds with one stone. I'm not sure how well that would work. Ransomware generally has responsive and helpful support people, because without that it…

> I'm referring to actual ransomware that works, that's done for profit. From what I have recently learned, this may no longer be accurate. The latest Risky Business happens to touch upon the subject. Criminal groups in Russia have financial arrangements with the central government, and may occasionally do some freelancing for them. Now China is getting on the same boat, but apparently with less entrepreneurial appro…

>If they are the only ones, I would be very much surprised. The net result is that ideological and for-profit motives will be harder to distinguish, as the same crew may well be doing different campaigns for different reasons at any given time.

Sure, some of the campaigns might be ransomware, some might be terrorism. I don't see how this disagrees with what I said.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#346
Russian hacker here (or "Criminal" I'm more honest than QC computing or anti virus scammers etc). The report is accurate but I told my fellas to stop attacking Hospitals. Brain is great. He gives me ideas for crime. My other friends just hate him.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#347
post #339
post #310

Earlier quoted context omitted.

Isn't terrorism trying to achieve a political goal through violence? Getting ransom money is just garden variety greed imo.

Terrorists often kidnap people and demand ransom, so I don't think the two are mutually exclusive.

Sure, that's a valid argument.

But I'm cynical, so I also think that terrorism is often just masqueraded greed, a money grab under the guise of doing something political.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#349

Why are hospital systems connected to the public internet, anyway? Wouldn't it make more sense to have all of the life-or-death stuff on its own secure network?

Very expensive to put and maintain separate cables, kinda separate internet.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#350

Earlier quoted context omitted.

How would the smart contract be able to validate that the 'keys' it releases are authentic before-hand?

You don't know this when interacting with the human ransomware people either, doesn't seem like a requirement.

Yep, makes sense.

I thought this proposal was some kind of pitch to solve that specific problem, not just automate the process after receiving a payment.

I just misunderstood what the goal was

Post reply on HN