Live data from Hacker News

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

krebsonsecurity.com

41–50 of 357 posts

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#42

Earlier quoted context omitted.

If we're honest, it's neither. It's 1000% profit-orientated.

Most state sponsored terrorism is profit-oriented

The expression "state sponsored terrorism" is vague and subject to a lot of biases. For what it's worth, most state-sanctioned cyberattacks are _not_ profit oriented. They rather aim to disrupt the operations of an organization (see: American cyberattacks against ISIL), establish deterrence (see: the US allegedly planting digital "bombs" in Russia's networks), collect intelligence (see: the OPM hack). The exception being North Korea, a state that conducts cyberattacks for the explicit purpose of making money.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#43
post #12

Earlier quoted context omitted.

Probably for initial infection it’s random but the negotiation for keys happens between real people. Thieves must be heartless to go after such desperate targets. But criminals always have ways of justifying things.

>but the negotiation for keys happens between real people I would be surprised if no one has written a smart contract for this yet - release the keys when X BTC are deposited to address Y.

Most enterprise ransomware payments involve actual negotiation/haggling on the price, timing, release of stolen data, etc.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#44
post #12

Earlier quoted context omitted.

Probably for initial infection it’s random but the negotiation for keys happens between real people. Thieves must be heartless to go after such desperate targets. But criminals always have ways of justifying things.

> Thieves must be heartless to go after such desperate targets. I mean it's the mafia, same people that traffic women and children, drugs,... profit is the motive, they don't care how. Just because they are now sitting behind a computer doesn't change their nature. I've been in a hospital recently and they were still running windows XP, my doctor using IE8 (cause activeX on the intranet) and Excel... But hey, they ru…

Lookup these Internet scammers videos on YouTube. These scammers are heartless. They terrorise old people when they don't comply, claim they are calling the police (on the victim for not paying fake invoices), even playing police siren sounds in the background. If they could scam a hospital they would in a heartbeat.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#46
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

In general, regulated entities are required to regularly prove that their change-management processes are sufficiently heavy as to make regular patching a non-starter.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#47
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

Is this the hospitals fault, or as software engineers and tech entrepreneurs, our fault?

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#48
post #8

This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.

Does anyone else feel that any organization that isn't doing regular secure backups with a way to restore that data deserves for this to happen? It like an airplane running out of gas because the pilot forgot to fill up the tank. Its kind of step one of working with computers.

I'm not sure that's of much comfort to the passengers on the plane.

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#49
post #10

Bad health IT is a public health issue. Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.

You could just have hospitals be required to meet FedRAMP compliance.

It is kind of crazy that hipaa compliance isn’t encompassing enough

Re: FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

#50
post #8

This is not what we need in these final chapters of 2020 with COVID cases spiking. > Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career. This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.

I sometimes wonder how much of Covid could've been spread by on purpose (asides from freedom fighters refusing common sense).
Post reply on HN