Ransomwared health insurer wasn't using anti-virus software
(2023/10/11)
- Reference: 1697007792
- News link: https://www.theregister.co.uk/2023/10/11/philhealth_ransomware_no_antivirus/
- Source link:
A recent ransomware attack on the Philippine Health Insurance Corporation (PhilHealth) occurred while the organization's antivirus software subscription had expired.
PhilHealth was attacked around September 22 and shut down many of its systems to battle an infection for which the Medusa ransomware gang claimed responsibility.
The incident saw a huge leak of personal information. PhilHealth was also slow to restore service, delaying medical matters for many.
[1]
Filipinos are justifiably outraged that their national health insurer was attacked and disrupted.
[2]
[3]
But they can express stronger emotions still – because on Monday local media outlet GMA's 24 Oras program [4]reported the attack took place while PhilHealth was not running antivirus software. The insurer's license had apparently lapsed several months before, but government procurement regulations made it impossible to renew.
It's not unusual for government agencies in developing nations to use unlicensed software, when commercial licenses are often priced beyond their means. In 2021, for example, The Register [5]covered an outage at Pakistan's Federal Board of Revenue that it swore could not have been caused by unpaid licenses because it caught up on its bills. Your correspondent also once spoke to a major vendor of design software that had 500 people show up to a conference in India – a nation in which it had sold no licenses and in which users felt they could pirate with impunity.
[6]
Whatever the reason for PhilHealth's security fail, its repercussions are serious: personal information has reached the dark web.
[7]Philippines decides outsourcers need incentives to stick around, after all
[8]Philippines orders fraud probe after paying MacBook prices for slow Celeron laptops
[9]It's 2023 and Sri Lanka doesn't have a cyber security authority
[10]Philippines logs on to Starlink for remote area internet services
The insurer on Sunday [11]posted a press release warning customers to ignore unexpected calls, messages, and emails asking for passwords and other information.
The insurer also "appealed to refrain from further circulating leaked data as it has dire consequences under the law," including up to 20 years in jail.
As if that will scare ransomware and phishing scum.
PhilHealth is presently using antivirus software – reportedly a trial license that expires in 30 days. ®
Get our [12]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZSZyQijhyqvi0O9XWgzszQAAAJI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZSZyQijhyqvi0O9XWgzszQAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZSZyQijhyqvi0O9XWgzszQAAAJI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.gmanetwork.com/news/topstories/nation/884665/philhealth-confirms-antivirus-had-expired/story/
[5] https://www.theregister.com/2021/08/26/pakistan_federal_board_of_revenue_software_licensing_snafus/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZSZyQijhyqvi0O9XWgzszQAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2022/09/19/philippines_outsourcer_incentives_retained/
[8] https://www.theregister.com/2022/08/16/philippines_laptop_procurement_fraud_probe/
[9] https://www.theregister.com/2023/05/26/sri_lanka_cybersecurity_authority/
[10] https://www.theregister.com/2022/07/28/starlink_philippines/
[11] https://www.facebook.com/PhilHealthOfficial/posts/pfbid0joFeRymVPbHGqBexHcv346Djdb6mjAqRGaFWSLsmsApUjKJgSWcs81or9f2anuU5l
[12] https://whitepapers.theregister.com/
PhilHealth was attacked around September 22 and shut down many of its systems to battle an infection for which the Medusa ransomware gang claimed responsibility.
The incident saw a huge leak of personal information. PhilHealth was also slow to restore service, delaying medical matters for many.
[1]
Filipinos are justifiably outraged that their national health insurer was attacked and disrupted.
[2]
[3]
But they can express stronger emotions still – because on Monday local media outlet GMA's 24 Oras program [4]reported the attack took place while PhilHealth was not running antivirus software. The insurer's license had apparently lapsed several months before, but government procurement regulations made it impossible to renew.
It's not unusual for government agencies in developing nations to use unlicensed software, when commercial licenses are often priced beyond their means. In 2021, for example, The Register [5]covered an outage at Pakistan's Federal Board of Revenue that it swore could not have been caused by unpaid licenses because it caught up on its bills. Your correspondent also once spoke to a major vendor of design software that had 500 people show up to a conference in India – a nation in which it had sold no licenses and in which users felt they could pirate with impunity.
[6]
Whatever the reason for PhilHealth's security fail, its repercussions are serious: personal information has reached the dark web.
[7]Philippines decides outsourcers need incentives to stick around, after all
[8]Philippines orders fraud probe after paying MacBook prices for slow Celeron laptops
[9]It's 2023 and Sri Lanka doesn't have a cyber security authority
[10]Philippines logs on to Starlink for remote area internet services
The insurer on Sunday [11]posted a press release warning customers to ignore unexpected calls, messages, and emails asking for passwords and other information.
The insurer also "appealed to refrain from further circulating leaked data as it has dire consequences under the law," including up to 20 years in jail.
As if that will scare ransomware and phishing scum.
PhilHealth is presently using antivirus software – reportedly a trial license that expires in 30 days. ®
Get our [12]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZSZyQijhyqvi0O9XWgzszQAAAJI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZSZyQijhyqvi0O9XWgzszQAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZSZyQijhyqvi0O9XWgzszQAAAJI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.gmanetwork.com/news/topstories/nation/884665/philhealth-confirms-antivirus-had-expired/story/
[5] https://www.theregister.com/2021/08/26/pakistan_federal_board_of_revenue_software_licensing_snafus/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZSZyQijhyqvi0O9XWgzszQAAAJI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2022/09/19/philippines_outsourcer_incentives_retained/
[8] https://www.theregister.com/2022/08/16/philippines_laptop_procurement_fraud_probe/
[9] https://www.theregister.com/2023/05/26/sri_lanka_cybersecurity_authority/
[10] https://www.theregister.com/2022/07/28/starlink_philippines/
[11] https://www.facebook.com/PhilHealthOfficial/posts/pfbid0joFeRymVPbHGqBexHcv346Djdb6mjAqRGaFWSLsmsApUjKJgSWcs81or9f2anuU5l
[12] https://whitepapers.theregister.com/
Re: Icing on the cake...
KittenHuffer
Probably couldn't enable M$ Pretender ..... I mean Defender, because their copies of Windoes are probably not licensed either!
Icing on the cake...
... but not the cake itself.
Very few AV applications can lay claim to being able to stop ransomware; the most ferocious (and successful) types morph far too quickly for software vendors to keep up.
Pointy steel-caps should be aimed at whatever inkling of an IT department they might have.
Aside: Was simply enabling Mickey$oft's included free AV too difficult? At least they then wouldn't have had to suffer the ridicule which is now undoubtedly smothering them.