News: 1601320618

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK, US hospital computers are down, early unofficial diagnosis is a suspected outbreak of Ryuk ransomware

(2020/09/28)


Universal Health Services, which operates over 400 hospitals and healthcare facilities in the US, Puerto Rico, and the UK, said on Monday that its IT network was offline due to an unspecified cybersecurity issue.

"We implement extensive IT security protocols and are working diligently with our IT security partners to restore IT operations as quickly as possible," the biz said in [1]a statement . "In the meantime, our facilities are using their established back-up processes including offline documentation methods."

UHS insists patient care continues to be delivered and that "no patient or employee data appears to have been accessed, copied or otherwise compromised."

A UHS spokesperson declined to provide further details or to comment on [2]unsubstantiated claims made via social media suggesting the involvement of the Ryuk ransomware family.

Unidentified individuals posting to Reddit who claim to be affiliated with UHS facilities in Arizona, California, Georgia, and Pennsylvania say the IT outage has affected their workplace. Such claims may also represent efforts by short sellers to influence stock prices, although UHS' share price has only declined slightly.

The Register has put in calls to several UHS facilities around the US but has not heard back from anyone in a position to confirm details about the nature of the IT outage or the number of facilities affected.

“There’s no doubt that an outage of this magnitude affects patient safety and care," said Tim Erlin, VP, product management and strategy at Tripwire, in response to an email from The Register . "This is a high stakes target for the attackers. If caught, they face significant liability for any loss of life incurred as a result."

Massachusetts city tells ransomware scumbags to RYUK off, our IT staff will handle this easily [3]READ MORE

He opined that ransomware doesn't strike suddenly and suggested the attack on UHS would have taken time to set up. "The widespread nature of this incident indicates a level of sophistication and that the attack was in the works for a relatively long period of time" he said.

Erlin urged those working at healthcare organizations to review their IT systems for vulnerabilities, to patch them diligently, and to review incident response plans.

"Successful incident response happens in the planning stages, before an incident; not while the incident is occurring," he said.

In March, those running ransomware operations using the DoppelPaymer and Maze malware [4]said they would refrain from targeting medical organizations during the COVID-19 pandemic. In light of subsequent events that doesn't seem to have had much effect.

German authorities recently [5]said that a woman had died as a result of treatment delays brought on by ransomware – the cyber-attack on the IT systems at a hospital in Dusseldorf forced a patient in need of urgent care to be taken to a facility in another city, and the delay in treatment led to her death. ®

Get our [6]Tech Resources



[1] https://www.uhsinc.com/statement-from-universal-health-services/

[2] https://www.reddit.com/r/hacking/comments/j17aj1/cyberattack_on_uhs_hospitals_nationwide_last_night/

[3] https://www.theregister.com/2019/09/06/ryuk_bedford_recovery/

[4] https://www.theregister.com/2020/03/19/ransomware_health_organisations/

[5] https://www.theregister.com/2020/09/23/doppelpaymer_german_hospital_ransomware/

[6] https://whitepapers.theregister.com/

Whack-A-Mole

Imhotep

I'm so glad I never worked on the IT security side of the house. What a thankless, impossible job.

Auntie Virus Software

Version 1.0

I run a mail server with two separate anti-virus checks on all incoming messages and attachments - normally everything works well but recently the number of emails with malware that slip through the AV software has increased dramatically. I fix the problem by quarantining all potentially suspicious attachments, naturally all Microsoft documents and every other potential risk ... how many lusers know that purchase_order.img is not a picture?

AV software is effective, it stops a lot of viruses but it's not 100% reliable, today we're getting deluged with DHL Overdue Invoice Notice - 1499320546.xls, Sales_Receipt_5782.xlsm, DHL_Paper_Works_Download _and_print_receipt.iso etc etc.

Anonymous Coward

UK Hospitals? Think that is a bit of CV like embellishment.

They are called computers simply because computation is the only significant
job that has so far been given to them.