News: 1621400347

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

New Zealand hospitals infected by ransomware, cancel some surgeries

(2021/05/19)


New Zealand's Waikato District Health Board (DHB) has been hit with a strain of ransomware that took down most IT services Tuesday morning and drastically reduced services at six of its affiliate hospitals.

The attack disabled all IT services except email. Patient notes became inaccessible, clinical services were disrupted, and surgeries postponed. Phone lines went down and hospitals were forced to accept urgent patients only.

Yesterday, Waikato DHB chief executive Kevin Snee [1]told local outlet Stuff that it could be days before systems are running again. In the meantime, hospital staff have turned to old fashioned pen and paper and referring non-emergency cases elsewhere.

[2]

[3]

[4]

Waikato DHB said today in a [5]canned statement:

Our staff are working to restore the infected systems and on the remediation process. We are working with the relevant government departments to ensure a secure environment is successfully re-established.

At affiliate Waikato Hospital, 29 out of 102 elective inpatient surgeries were postponed today. Yesterday, six out of 101 were cancelled. At affiliate Thames Hospital, all elective surgeries were postponed. All outpatient activity was deferred at affiliate hospitals in rural areas.

The organisation added:

We are currently working with other government departments to investigate the cause, but are working on the theory that the initial incursion was via an email attachment. A forensic investigation is ongoing.

The head of Waikato DHB has decided not to pay a ransom, a decision also made by the Scottish Environmental Protection Agency when it was [6]attacked by WizardSpider-deployed Conti malware last January.

The Kiwi infection follows [7]WizardSpider's attack last week that resulted in a Irish hospital cancelling outpatient appointments.

[8]Colonial Pipeline suffers server gremlins, says it's not due to another ransomware infection

[9]Axa insurance offshoots pwned as Ireland reveals second ransomware hit

[10]48 ways you can avoid file-scrambling, data-stealing miscreants – or so says the Ransomware Task Force

[11]Emotet malware self-destructs after cops deliver time-bomb DLL to infected Windows PCs

Several ransomware operators have [12]pledged that they will not target medical organisations during the current pandemic, but apparently both honour and consistency is lacking among thieves.

The Register understands that institutions and businesses with ties to the hospital system have been alerted to the situation, are aware of the potential for the ransomware infection to spread quickly, and are acting accordingly to protect their operations. ®

Get our [13]Tech Resources



[1] https://www.stuff.co.nz/national/125163367/no-ransom-will-be-paid--waikato-hospitals-reeling-after-cyber-attack

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YKThvOxwkMXkoHe39WxhmAAAAFA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YKThvOxwkMXkoHe39WxhmAAAAFA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YKThvOxwkMXkoHe39WxhmAAAAFA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.waikatodhbnewsroom.co.nz/2021/05/19/waikato-dhb-information-system-update/

[6] https://www.theregister.com/2021/01/22/sepa_ransomware_failure/

[7] https://www.theregister.com/2021/05/14/ireland_hse_ransomware_hospital_conti_wizardspider/

[8] https://www.theregister.com/2021/05/18/colonial_pipeline_server_outage/

[9] https://www.theregister.com/2021/05/17/ransomware_roundup/

[10] https://www.theregister.com/2021/04/29/ransomware_task_force_offers_48/

[11] https://www.theregister.com/2021/04/26/emotet_sunday_25_april_killswitch_date/

[12] https://www.theregister.com/2020/03/19/ransomware_health_organisations/

[13] https://whitepapers.theregister.com/

Jamesit

A possible solution is a separate system for email that has no access to the important office network, I don't think that would be too hard to setup.

Or as we spell it

Anonymous Coward

Honour

I saw this when doing support for a Car Manufacturer

Anonymous Coward

Users where TOLD not to open attachments, clear and simple so one user opened one and encrypted not only his data but also data on network shares. There was an imaginary line of Techies who wanted to give him a slap. So it was down to us to restore the Backups and retrieve the Tapes.

Potemkine!

It seems that email phishing is the main reason for successful ransomware attacks, doesn't it?

There are many technical answers at different levels (firewall, mail server, client) to mitigate, but the most efficient one is users education. And by education I mean repeat the information again and again.

Pascal Monett

Totally agree.

Unfortunately, we're talking hospital here. Nurses have other things to do than follow security seminars on email handling. Especially when governments are notorious for cutting down on healthcare spending.

Hospital personnel have been overworked for years, it's not new.

I don't know what the solution is, but to me it should be before the email reaches the inbox. Maybe have a system that scans email contents, quarantines anything with a link for further analysis, then checks all links for acceptability before depositing them at their destination.

The point is hospitals need better email scanning because the personnel doesn't have the time to think about it. It's the email filter that needs to up its game.

"The attack disabled all IT services except email"

Pascal Monett

Ain't that a shame. It took everything down except for the vector it used to get in.

Irony, anyone ?

Go away! Stop bothering me with all your "compute this ... compute that"!
I'm taking a VAX-NAP.

logout