Irish Health Service ransomware attack happened after one staffer opened malware-ridden email
(2021/12/10)
- Reference: 1639170307
- News link: https://www.theregister.co.uk/2021/12/10/ireland_health_conti_ransomware_attack_report/
- Source link:
Ireland's Health Service Executive (HSE) was almost paralysed by ransomware after a single user opened a malicious file attached to a phishing email, a consultancy's damning report has revealed.
Issued today, the report from PWC (formerly known as PriceWaterhouseCoopers) said that the hugely harmful Conti ransomware infection was caused because of the simplest attack vector known to infosec: spam.
PWC said, in the report's executive summary:
[1]
"The Malware infection was the result of the user of the Patient Zero Workstation clicking and opening a malicious Microsoft Excel file that was attached to a phishing email sent to the user on 16 March 2021."
[2]
[3]
Even worse, PWC said HSE personnel had spotted the WizardSpider crew behind the infection operating on HSE networks – yet "these did not result in a cybersecurity incident and investigation initiated by the HSE".
"As a result, opportunities to prevent the successful detonation of the ransomware were missed".
[4]
PWC also said that the WizardSpider criminal crew who pwned the HSE probably "exploited an unpatched known vulnerability" to gain access to the HSE's Active Directory domain. The vuln was not identified in its full report, potentially suggesting it may still exist in corners of the HSE network.
[5]Spar shops across northern England shut after cyber attack hits payment processing abilities
[6]Utility biz Delta-Montrose Electric Association loses billing capability and two decades of records after cyber attack
[7]Visiting a booby-trapped webpage could give attackers code execution privileges on HP network printers
[8]Lloyd's of London suggests insurers should not cover 'retaliatory cyber operations' between nation states
[9]Kremlin names the internet giants it will kidnap the Russian staff of if they don't play ball in future
HSE chairman Ciarán Devane said in a canned statement today: “It is clear that our IT systems and cybersecurity preparedness need major transformation. This report highlights the speed with which the sophistication of cyber-criminals has grown, and there are important lessons in this report for public and private sector organisations in Ireland and beyond.”
The HSE was found wanting in its own after-action review, the exec summary of which [10]is downloadable here as an 18-page PDF. The full report is 157 pages long ( [11]PDF ) and includes colourful graphics and charts too.
Ireland's National Cyber Security Centre (INCSC) [12]named the ultimate payload, executed two months after initial access was established, as Conti v3; a 32-bit executable that encrypts all within its grasp.
Two months after gaining access, Conti hit the big red button: a large part of Ireland's health service lost its IT systems as responders struggled to contain the ransomware infection. Before that, however, antivirus on HSE endpoints detected both Cobalt Strike and Mimikatz being deployed on the so-called Patient Zero workstation.
[13]
In a five-day timespan during early May 2021, WizardSpider had compromised systems in five separate hospitals, pwning a further three by 12 May. Although the hospital's internal security team were notified by its external "cybersecurity solutions provider" to unusual alerts, not enough action was taken before WizardSpider deployed their main Conti ransomware payload on 14 May.
We saw, we came, we conquered
There was a late chance to stop the ransomware extortionists which was missed, as PWC recounted:
On 10 May 2021, Hospital C asked Hospital C’s cybersecurity solutions provider whether they should be concerned about Cobalt Strike alerts. They were advised by Hospital C’s cybersecurity solutions provider that since the threat had been remediated by their antivirus software, their risk was low. Hospital C did not initiate a cyber incident response investigation.
The antivirus provider was not named in the PWC report.
Meanwhile, another hospital initiated its incident response plan. This resulted in 4,500 passwords being reset, firewall config changes being made and lots of similar security-related activity. Unfortunately, despite that hospital telling the central HSE team they had identified suspicious activity on two HSE servers, the HSE "incorrectly concluded in an email between the HSE teams that the suspicious activity originated from Hospital A, rather than the other way round."
The report, an unusually candid document to be made public, will be fascinating reading for any organisation trying to better prepare itself for one of the worst security threats of all. Doubtless it'll be useful to infosec managers too as their orgs move into budget-setting mode for 2022. ®
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YbPcJrOUZGu-wlkZgLCjkQAAAMs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YbPcJrOUZGu-wlkZgLCjkQAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YbPcJrOUZGu-wlkZgLCjkQAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YbPcJrOUZGu-wlkZgLCjkQAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2021/12/06/spar_cyber_attack/
[6] https://www.theregister.com/2021/12/03/dmea_colorado_cyber_attack_billing_systems/
[7] https://www.theregister.com/2021/11/30/exploitable_hp_enterprise_printers_f_secure/
[8] https://www.theregister.com/2021/11/30/lloyds_london_cyber_insurance_clauses/
[9] https://www.theregister.com/2021/11/25/tech_offices_russia/
[10] https://regmedia.co.uk/2021/12/10/ireland_hse_ransomware_exec_summary_pwc_report.pdf
[11] https://regmedia.co.uk/2021/12/10/ireland_hse_ransomware_full_pwc_report.pdf
[12] https://www.theregister.com/2021/05/17/ransomware_roundup/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YbPcJrOUZGu-wlkZgLCjkQAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://whitepapers.theregister.com/
Issued today, the report from PWC (formerly known as PriceWaterhouseCoopers) said that the hugely harmful Conti ransomware infection was caused because of the simplest attack vector known to infosec: spam.
PWC said, in the report's executive summary:
[1]
"The Malware infection was the result of the user of the Patient Zero Workstation clicking and opening a malicious Microsoft Excel file that was attached to a phishing email sent to the user on 16 March 2021."
[2]
[3]
Even worse, PWC said HSE personnel had spotted the WizardSpider crew behind the infection operating on HSE networks – yet "these did not result in a cybersecurity incident and investigation initiated by the HSE".
"As a result, opportunities to prevent the successful detonation of the ransomware were missed".
[4]
PWC also said that the WizardSpider criminal crew who pwned the HSE probably "exploited an unpatched known vulnerability" to gain access to the HSE's Active Directory domain. The vuln was not identified in its full report, potentially suggesting it may still exist in corners of the HSE network.
[5]Spar shops across northern England shut after cyber attack hits payment processing abilities
[6]Utility biz Delta-Montrose Electric Association loses billing capability and two decades of records after cyber attack
[7]Visiting a booby-trapped webpage could give attackers code execution privileges on HP network printers
[8]Lloyd's of London suggests insurers should not cover 'retaliatory cyber operations' between nation states
[9]Kremlin names the internet giants it will kidnap the Russian staff of if they don't play ball in future
HSE chairman Ciarán Devane said in a canned statement today: “It is clear that our IT systems and cybersecurity preparedness need major transformation. This report highlights the speed with which the sophistication of cyber-criminals has grown, and there are important lessons in this report for public and private sector organisations in Ireland and beyond.”
The HSE was found wanting in its own after-action review, the exec summary of which [10]is downloadable here as an 18-page PDF. The full report is 157 pages long ( [11]PDF ) and includes colourful graphics and charts too.
Ireland's National Cyber Security Centre (INCSC) [12]named the ultimate payload, executed two months after initial access was established, as Conti v3; a 32-bit executable that encrypts all within its grasp.
Two months after gaining access, Conti hit the big red button: a large part of Ireland's health service lost its IT systems as responders struggled to contain the ransomware infection. Before that, however, antivirus on HSE endpoints detected both Cobalt Strike and Mimikatz being deployed on the so-called Patient Zero workstation.
[13]
In a five-day timespan during early May 2021, WizardSpider had compromised systems in five separate hospitals, pwning a further three by 12 May. Although the hospital's internal security team were notified by its external "cybersecurity solutions provider" to unusual alerts, not enough action was taken before WizardSpider deployed their main Conti ransomware payload on 14 May.
We saw, we came, we conquered
There was a late chance to stop the ransomware extortionists which was missed, as PWC recounted:
On 10 May 2021, Hospital C asked Hospital C’s cybersecurity solutions provider whether they should be concerned about Cobalt Strike alerts. They were advised by Hospital C’s cybersecurity solutions provider that since the threat had been remediated by their antivirus software, their risk was low. Hospital C did not initiate a cyber incident response investigation.
The antivirus provider was not named in the PWC report.
Meanwhile, another hospital initiated its incident response plan. This resulted in 4,500 passwords being reset, firewall config changes being made and lots of similar security-related activity. Unfortunately, despite that hospital telling the central HSE team they had identified suspicious activity on two HSE servers, the HSE "incorrectly concluded in an email between the HSE teams that the suspicious activity originated from Hospital A, rather than the other way round."
The report, an unusually candid document to be made public, will be fascinating reading for any organisation trying to better prepare itself for one of the worst security threats of all. Doubtless it'll be useful to infosec managers too as their orgs move into budget-setting mode for 2022. ®
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YbPcJrOUZGu-wlkZgLCjkQAAAMs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YbPcJrOUZGu-wlkZgLCjkQAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YbPcJrOUZGu-wlkZgLCjkQAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YbPcJrOUZGu-wlkZgLCjkQAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2021/12/06/spar_cyber_attack/
[6] https://www.theregister.com/2021/12/03/dmea_colorado_cyber_attack_billing_systems/
[7] https://www.theregister.com/2021/11/30/exploitable_hp_enterprise_printers_f_secure/
[8] https://www.theregister.com/2021/11/30/lloyds_london_cyber_insurance_clauses/
[9] https://www.theregister.com/2021/11/25/tech_offices_russia/
[10] https://regmedia.co.uk/2021/12/10/ireland_hse_ransomware_exec_summary_pwc_report.pdf
[11] https://regmedia.co.uk/2021/12/10/ireland_hse_ransomware_full_pwc_report.pdf
[12] https://www.theregister.com/2021/05/17/ransomware_roundup/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YbPcJrOUZGu-wlkZgLCjkQAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://whitepapers.theregister.com/
Patient Zero?
Patient fucking Zero? Is that shorthand for "clown who opened an attachment?" Or maybe shorthand for "person who the clowns that pass for opsec didn't tell said "patient" not to open attachments and absolutely not click on links in email
But the excuse gets better...
Quote " This report highlights the speed with which the sophistication of cyber-criminals has grown, and there are important lessons in this report for public and private sector organisations in Ireland and beyond.” unquote.
I have to ask, has the sophistication and growth of your security not matched theirs? Indeed, Has it grown at all?
And please lose the shite about "lessons". You obviously learn't no lessons from other companies breaches. So, what is so important about your utter failure, that other companies should learn? Could it be security needs beefing up, but as it will cost money, we'll just go with the solution as in "fuck it, we'll just hope for the best"?
And whilst you are at it, lose the word "cyber". When used in this commonly used excuse for a fuck up, it just makes the user sound like a clueless twat. Oh wait....