News: 1620992715

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Hospitals cancel outpatient appointments as Irish health service struck by ransomware

(2021/05/14)


Ireland's nationalised health service has shut down its IT systems following a "human-operated" Conti ransomware attack, causing a Dublin hospital to cancel outpatient appointments.

The country's Health Service Executive closed its systems down as a precaution, local reports from the Irish public service broadcaster RTÉ said, reporting that Dublin's Rotunda Hospital had cancelled appointments for outpatients – including many for pregnant women.

"The maternity hospital said all outpatient visits are cancelled - unless expectant mothers are 36 weeks pregnant or later," reported RTÉ, adding: "All gynaecology clinics are also cancelled today."

[1]

[2]

[3]

Ireland's National Maternity Hospital, also in Dublin, was similarly affected.

There is a significant ransomware attack on the HSE IT systems. We have taken the precaution of shutting down all our our IT systems in order to protect them from this attack and to allow us fully assess the situation with our own security partners. — HSE Ireland (@HSELive) [4]May 14, 2021

Fergal Malone, chief of the Rotunda Hospital and a senior HSE bod, said: "There has been a significant ransomware attack on the HSE IT systems. They have taken the precaution of shutting down all their IT systems in order to protect them from this attack and to allow the HSE to fully assess the situation with their security partners. The HSE apologises for the inconvenience to patients and to the public."

Paul Reid, HSE chief exec, told Ireland's Newstalk FM radio station that the ransomware was "human-operated" and appeared to be the Conti strain:

Paul Reid says the major ransomware attack targeting the HSE is "quite sophisticated", while the COVID-19 vaccination programme isn't impacted as it's on a different system. [5]@NTBreakfast [6]pic.twitter.com/XXtzlzBQAV — NewstalkFM (@NewstalkFM) [7]May 14, 2021

"We have been the subject of a major ransomware attack… it's what's known as a Conti human-operated attack to get access to data," Reid told the radio station.

He added in a separate interview that the Irish Defence Forces' cybersecurity personnel were helping with the response. So far no ransom demand has been disclosed by the HSE and nothing related to HSE has appeared on Conti's Tor leaks blog.

Conti deployed by WizardSpider crew

Conti previously targeted the Scottish Environmental Protection Agency, though that January attack left the criminals empty-handed [8]after SEPA wisely decided not to pay . The same criminals were behind [9]the compromise of British clothing retailer Fatface , successfully stealing personal data and payment card details in the process.

William Thomas, a researcher from infosec firm Cyjax, told The Register : "Conti is a human-operated ransomware strain linked to a cybercriminal gang tracked by the private industry as WizardSpider. It has leaked the highest number of victims to its darknet wall of shame, at 339 by my count.

|Its connections to Ryuk ransomware are also significant as it has also gone after hospitals in the US and France. Conti's typical initial access vector is via malicious spam campaigns pushing BazarLoader or Trickbot; Cobalt Strike continues to be the ransomware operators' tool of choice."

Crowdstrike's [10]summary of WizardSpider pegs the gang as being "Russia-based" and mostly "opportunistic" in its targeting. The criminals' activity was "sporadic during the first half of 2020" but increased after they began using Conti, with Crowdstrike saying: "Conti victims span multiple sectors and geographies, the vast majority of which are based in North America and Europe."

[11]

Sophos reckons the Conti malware deploys through [12]the (ab)use of Cobalt Strike , with the company's [13]detailed analysis highlighting that Conti's operators use the double-extortion ransomware business model: encrypt the target network after exfiltrating data and demand a ransom both for the decryption utility and to "prevent" publication of the data. Obviously nobody can guarantee that criminals stick to their promises.

Reg reader Pat speculated to us that the ransomware hadn't reached every part of the HSE's IT estate: "The HSE vaccination IT system seems to use Salesforce, from looking at the headers of my registration email, so maybe that's why news reports are saying that is unaffected."

Ransomware attacks on healthcare organisations have slowly become the norm. As the COVID-19 pandemic took hold worldwide in March 2020 a handful of prominent extortionist gangs [14]promised not to attack hospitals and medical research institutes.

[15]

This [16]lasted all of six months as criminal gangs, largely based in Russian-speaking countries, realised that healthcare organisations were more likely to pay ransoms immediately than other sectors that could cope without their IT systems for days or weeks at a time. ®

Get our [17]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJ6emkaFsC-BZIfg1dfTJgAAAEY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJ6emkaFsC-BZIfg1dfTJgAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJ6emkaFsC-BZIfg1dfTJgAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://twitter.com/HSELive/status/1393090933361623042?ref_src=twsrc%5Etfw

[5] https://twitter.com/NTBreakfast?ref_src=twsrc%5Etfw

[6] https://t.co/XXtzlzBQAV

[7] https://twitter.com/NewstalkFM/status/1393113568829231106?ref_src=twsrc%5Etfw

[8] https://www.theregister.com/2021/01/22/sepa_ransomware_failure/

[9] https://www.theregister.com/2021/03/24/fatface/

[10] https://www.crowdstrike.com/blog/wizard-spider-adversary-update/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJ6emkaFsC-BZIfg1dfTJgAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://www.theregister.com/2020/09/24/cobalt_strike_cisco_talos/

[13] https://news.sophos.com/en-us/2021/02/16/conti-ransomware-evasive-by-nature/

[14] https://www.theregister.com/2020/03/19/ransomware_health_organisations/

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJ6emkaFsC-BZIfg1dfTJgAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[16] https://www.theregister.com/2020/10/29/ryuk_ransomware_us_hospitals_warning/

[17] https://whitepapers.theregister.com/

That's a change...

John Riddoch

This was only a "quite sophisticated" attack, as opposed to the "highly sophisticated" attacks most organisations are targeted with.

Re: That's a change...

Mike 137

' opposed to the "highly sophisticated" attacks '

Oh, you mean the ones that emerge on investigation every time to have been total push-overs?

This is very serious

Anonymous Coward

This appears to have been a deliberate and targeted attack on the Health System of an EU nation.

Re: This is very serious

Richard Jones 1

So no doubt Brussels and what passes for its leader, Ursula What-ever, will give the problem a stern talking to and suggest that it is barred from the EU,

Despicable

Pascal Monett

I think this calls for a DDoHS : Direct Denial of Hospital Service - to be administered with a 9mm. Maybe even a Beretta.

Sanctions?

anthonyhegedus

When are we going to issue sanctions against countries that harbour these criminals? And of course countries that sponsor them or even are them.

The situation has got so serious that the only solutions are incredibly uncomfortable: increased security costs, decreased convenience, even vetting employees.

"...Conti malware deploys through the (ab)use of Cobalt Strike"

Mike 137

Cobalt Strike. So the target failed a stringent pen test then.

Perhaps they're relying on the wrong tools for their own testing (supposing they do any).

I'm increasingly annoyed by the almost universal assumption of "adequate security" that never gets properly tested except by the bad guys.

You get the security you put sufficient and appropriate effort into.

Reg Webcast ?

Miss Config

Serious question :

The Reg has a webcast about ransomware on May 26 :

https://www.theregister.com/2021/05/12/learn_to_frustrate_modern_ransomware/

will everybody who attends this webcast learn how to avoid at least this particular kind of ransomware attack ?

Doctor Syntax

It might be a good move for Health Services (and similar organisations) to instruct the local offices to run an overnight job to print out next days' appointments and explain why. The explanation might at least concentrate minds and the print-out should avoid cancellations for the next day and give the clean-up a day's start.

Of course going back to something as old-fashioned as paper might offend those who thought it would be a good idea not to have fax, pagers or the like as backup.

Anonymous Coward

Most departments are meant to have business continuity plans in place to keep running when this happens. Many do not test it.

It's typically because senior managers do not mandate it and more importantly SUPPORT testing of it.

I wonder if....

Anonymous Coward

...That due to COVID their policy of "1 device, 1 person" to help with remote working they'll be able to point the finger at the ingress point. Apparently users were contacted by text message at 7am saying something along the lines of "Don't switch your laptop on".

"Since when has a dictator ever been benign? I hear all this
libertarian garbage being spouted from the "linux community",
and then have people apparently celebrate the existance of a
dictatorship..."

- Michael W. Zappe