News: 1590522661

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

If someone could stop hackers pwning medical systems right now, that would be cool, say Red Cross and friends

(2020/05/26)


Following the surge of cyber attacks on medical facilities, the head of the International Committee of the Red Cross (ICRC) and more than 40 other international leaders asked the governments of the world to do more to safeguard critical medical organizations amid the coronavirus pandemic.

In an [1]open letter published on Tuesday, Peter Maurer, president of the ICRC, and other prominent signatories asked the world's government's "to take immediate and decisive action to stop all cyber attacks on hospitals, health care and medical research facilities, as well as on medical personnel and international public health organizations."

In recent weeks, the letter says, there have been cyber attacks on healthcare facilities in the Czech Republic, France, Spain, Thailand, and the US, among others.

Last month, the US Cybersecurity and Infrastructure Security Agency (CISA) [2]warned about "a growing use of COVID-19-related themes by malicious cyber actors." Also in April, Google [3]reported that its security systems were catching "18 million malware and phishing Gmail messages per day related to COVID-19, in addition to more than 240 million COVID-related daily spam messages."

And the World Health Organization said it had seen an [4]uptick in online attacks on its staff and the general public.

Surprise surprise! Hostile states are hacking coronavirus vaccine research, warn UK and USA intelligence [5]READ MORE

However, the call to have governments cooperate to fight attacks on healthcare organizations may not go so well if, as US authorities have claimed, governments are behind some of the hacking. Earlier this month, the FBI and CISA [6]said they are investigating attempts to compromise US organizations conducting COVID-19 research to steal research data.

Nonetheless, the ICRC argues that the world has agreed to spare healthcare facilities from attack during wartime and we should not tolerate internet attacks either.

The Register asked the ICRC what it hopes to accomplish by demanding governments do more, given that nations already oppose illegal hacking and attempt to apprehend miscreants. We've not received a response.

In an email to The Register , Mike Hamilton, CISO at CI Security, a cybersecurity biz focused on the health sector, expressed skepticism that miscreants will moderate their behavior because the ICRC has raised the alarm but suggested that more international cooperation might help.

"I don’t think the ransomware operators, [business email compromise] fraudsters, etc. will give up by being asked," he said. "Note how bad unemployment impersonation fraud is right now – criminals stealing from people that are really down (bastards)."

"However, if governments talk and make some agreements this may have the potential to start treating our logical borders like our physical borders: if you don’t maintain a standard of behavior (speaking to country X), we lock out your legit business traffic and your business leaders can go scream to [political] leaders to fix things." ®



[1] https://www.icrc.org/en/document/governments-work-together-stop-cyber-attacks-health-care

[2] https://www.us-cert.gov/ncas/alerts/aa20-099a

[3] https://blog.google/technology/safety-security/threat-analysis-group/findings-covid-19-and-online-security-threats/

[4] https://www.who.int/news-room/detail/23-04-2020-who-reports-fivefold-increase-in-cyber-attacks-urges-vigilance

[5] https://www.theregister.co.uk/2020/05/05/coronavirus_research_hacking/

[6] https://www.fbi.gov/news/pressrel/press-releases/peoples-republic-of-china-prc-targeting-of-covid-19-research-organizations

Dwarf

Whilst their logic may be good, I wonder if anyone has explained to them that the attacker doesn't know what the endpoint is, nor do they generally care.

Its easy to see why the compromised will happen since people click links with interesting titles and pandemics definitely tick the box for that.

The only way to really fix this issue is to ensure that the tools that you need to do your job are properly protected, a bit like how you lock the the other things in the hospitals and vehicles. Its time for organisations world-wide to realise that IT security budgets are really important and that its not wasted money. On the other hand, paying a scammer is.

Anonymous Coward

We make medical devices and saw a big uptick in malware deliveries after they added a COVID statement to the corporate web site. I expect that in today's world the malware is delivered by bots, not people who only get involved once the malware executes.

veti

That's true for the regular spammed attacks, but there's a whole lot of spear phishing and other highly aimed hacking that's being directed at the medical industry right now.

If I had to speculate, I'd guess it's happening because unaccustomed amounts of public funds are being poured very quickly into medical care and research. Anytime that sort of money is sloshing about in places that aren't fully accustomed to it, there will be opportunities for scumbags to siphon some of it off.

Haven't they heard of the Streisand effect?

sad_loser

I work in medical informatics and the sad fact is that most of the kit is abysmally bad, and is held together with the IT equivalent of duct tape, and completely deserves to be hacked.

The root cause for this is that there is still a mindset in healthcare that good data / information is a 'nice to have' rather than being part of the core.

To its credit, this is something that HMG have been actively trying to remedy and this increased post Wannacry.

There are good standards in healthcare IT e.g. 27001 / 13485 / OWASP but they are not properly enforced, and we have got a load of cowboy wannabe healthcare IT clowns who have been allowed to deliver kit that is not up to scratch.

Obvious answer is obvious.

jake

"The Register asked the ICRC what it hopes to accomplish by demanding governments do more"

Because they want to get into more column-inches, silly!

Hacking hospitals costs lives

Blackjack

No matter how you may feel about certain medical institutions, messing up with their computers systems can has has ended with the loss of life.

"ICRC argues that the world has agreed to spare healthcare facilities from attack during wartime"

Anonymous Coward

Well that's going well then. It appears that it has become standard practice to bomb all hospitals and schools as "first class" targets - at least in certain parts of the world.

And, as a programmer. I am paid to split hairs, so I will: it isn't wartime in most of the world and therefore that agreement clearly isn't relevant - however the fourth estate wants to style the pandemic and our efforts to contain it.

And, don't forget, there countries out there that would love to sow discord and confusion in "The West" so are unlikely to do anything about all that clearly targeted BOT action any time soon.

indent does _not_ solve the problem of:
* buggers who introduce wrappers for standard kernel stuff - like,
say it, typedef int Int32; and sprinkle their crap with
per-architecture ifdefs.

- Alexander Viro on coding style