Live data from Hacker News

Irish health service hit by cyber attack

bbc.co.uk

51–60 of 156 posts

Re: Irish health service hit by cyber attack

#51

A lot of these articles don't actually mention specifically how the systems were compromised. Was it a malicious email attachment that propagated through unsecured networks or outdated OS versions? And what data was encrypted? Are we talking regular excel files or actual databases? It would be interesting to have some more detail or case studies so others could know how to fortify infection points and limit the blast…

The media are keen to cover the story ASAP. It can take some time to do an investigation.

Re: Irish health service hit by cyber attack

#52

A lot of these articles don't actually mention specifically how the systems were compromised. Was it a malicious email attachment that propagated through unsecured networks or outdated OS versions? And what data was encrypted? Are we talking regular excel files or actual databases? It would be interesting to have some more detail or case studies so others could know how to fortify infection points and limit the blast…

My guess is that it's not mentioned because they don't know (yet).

A lot of places that get crippled by ransomware have outdated or underfunded IT departments (health care is particularly bad at this), so that kind of insight is barely on the table at the best of times.

Even when a postmortem is eventually done, companies don't want to have to admit the attack could have been prevented, or at least minimized, with better investment in security.

Re: Irish health service hit by cyber attack

#54

There's a trend of paying these ransomware attacks which are sometimes in the order of millions. Imagine if those millions were _proactively_ invested into the computer security of these systems?

I hope this train of thought becomes more mainstream.

Re: Irish health service hit by cyber attack

#55

A lot of these articles don't actually mention specifically how the systems were compromised. Was it a malicious email attachment that propagated through unsecured networks or outdated OS versions? And what data was encrypted? Are we talking regular excel files or actual databases? It would be interesting to have some more detail or case studies so others could know how to fortify infection points and limit the blast…

So I don't have details on this specific case, but I did work in cybersecurity and can comment on the vast majority of similar cases I saw, including some which made the front page. Every single one I remember came from unpatched OS vulnerabilities for which the patch was already available.

Regular patching is necessary hygiene for corporate IT, but often the department is understaffed, or frankly told by management to prioritize shiny things instead.

Re: Irish health service hit by cyber attack

#56
post #42

Earlier quoted context omitted.

apparently the traceability of digital currencies is proving effective in tracking down criminals that might otherwise operate in just cash.

So, did they get the people that r'wared the US pipeline then?

Infosec Twitter this morning seems to imply that perhaps they did.

https://twitter.com/hashtag/REvil?src=hashtag_click&f=live

caveat that this world is full of rampant speculation and lies so take it with a grain of salt. ;-)

Re: Irish health service hit by cyber attack

#57
post #19

You'd have to think that sooner or later they are going to get into one of the big cloud providers and cause havoc.

(Usually) - Those cloud providers know what they're doing though and de-couple things as much as possible, reducing and entire system compromise. It's their bread and butter, I would much prefer them managing the systems than the HSE.

Sure, I don't disagree. But in many cases the value of the data lost even over a short period can dwarf the size of a ransom, as can losses from downtime before getting operations up and running again. Can you imagine if they managed to take down e.g. S3, even for a day? The incentive to pay would be high, which in turn increases its attractiveness as a target. Not saying they would pay of course.

Re: Irish health service hit by cyber attack

#58

A lot of these articles don't actually mention specifically how the systems were compromised. Was it a malicious email attachment that propagated through unsecured networks or outdated OS versions? And what data was encrypted? Are we talking regular excel files or actual databases? It would be interesting to have some more detail or case studies so others could know how to fortify infection points and limit the blast…

So I don't have details on this specific case, but I did work in cybersecurity and can comment on the vast majority of similar cases I saw, including some which made the front page. Every single one I remember came from unpatched OS vulnerabilities for which the patch was already available. Regular patching is necessary hygiene for corporate IT, but often the department is understaffed, or frankly told by management…

Most corporate machines aren't directly on the internet though... How do attackers get through corporate firewalls to access said unpatched machines?

I would guess the easiest way is to phish a login to the corp VPN or to send an email with a malicious attachment to give the attacker something inside the corp firewall as a place to start their port scan of the internal network and begin their attacks.

Re: Irish health service hit by cyber attack

#59
post #54

There's a trend of paying these ransomware attacks which are sometimes in the order of millions. Imagine if those millions were _proactively_ invested into the computer security of these systems?

I hope this train of thought becomes more mainstream.

Politicians always seem to be scared to front-load costs.

Happens with military/infrastructure spending all the time - get a cheap initial quote and then get screwed long-term.

And with covid. Govs didn't have the courage to lock down early and fast / close borders and cost themselves a lot of money in the short term.

Post reply on HN