News: 1702324868

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

2.5M patients infected with data loss in Norton Healthcare ransomware outbreak

(2023/12/11)


Norton Healthcare, which runs eight hospitals and more than 30 clinics in Kentucky and Indiana, has admitted crooks may have stolen 2.5 million people's most sensitive data during a ransomware attack in May.

During the intrusion, the criminals accessed names, contact information, Social Security Numbers, dates of birth, and may have included may have also included driver's license and government ID numbers, financial account information, and digital signatures.

Health information, insurance information, and medical ID numbers belonging to former patients, employees, and employee dependents and beneficiaries was also at risk, according to a data breach disclosure [1]filed with the Maine Attorney General's office.

[2]

The not-for-profit healthcare system said it discovered the security incident, later determined to be a ransomware infection, on May 9, two days after the intrusion.

[3]

[4]

"Our investigation determined that an unauthorized individual(s) gained access to certain network storage devices between May 7, 2023, and May 9, 2023, but did not access Norton Healthcare's medical record system or Norton MyChart," Norton said in a [5]statement on its website.

"Norton Healthcare notified the FBI and immediately began investigating this incident with the assistance of outside legal counsel and a respected forensic security provider," according to the breach event report

[6]PDF

.

[7]

"Norton did not make any ransom payment," it added.

AlphV/BlackCat ransomware affiliates [8]claimed responsibility for the theft, and listed the healthcare system on its leak site on May 25.

Norton declined to answer The Register 's specific questions about the intrusion, including if AlphV was behind the breach.

[9]

"Norton Healthcare takes the personal information of our patients and employees seriously," spokesperson Renee Murphy told The Register . "Measures are being taken to further enhance our network security safeguards. There is pending litigation in this matter and we refer you to our public notice posted on our website."

[10]Canada goosed as attackers shutter hospitals and China deepfakes its politicians

[11]Now BlackCat extortionists threaten to leak stolen plastic surgery pics

[12]BlackCat ransomware crims threaten to directly extort victim's customers

[13]Scores of US credit unions offline after ransomware infects backend cloud outfit

This latest case comes as US hospitals and healthcare systems face skyrocketing levels of ransomware infections. In addition to disclosing [14]very sensitive personal information , these intrusions have led to weeks-long outages, diverted ambulances and [15]delayed medical treatment for patients or their death - in at least [16]one case .

At least [17]36 US health systems that oversee 130 hospitals have experienced ransomware attacks this year, and the criminals stole data in at least 27 of these instances, according to Emsisoft threat analyst Brett Callow.

The US Department of Health and Human Services reported a 93 percent increase in "large breaches" between 2018 and 2022 — the number jumped from 369 to 712

[18]PDF

. It also saw a 278 percent increase in large breaches involving ransomware during this time period. ®

Get our [19]Tech Resources



[1] https://apps.web.maine.gov/online/aeviewer/ME/40/0d29d7d3-48c2-4879-b6c7-32360396bd04.shtml

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZXeUmrQvEtNZ7GcdZQSmzAAAAAM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXeUmrQvEtNZ7GcdZQSmzAAAAAM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXeUmrQvEtNZ7GcdZQSmzAAAAAM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://nortonhealthcare.com/news/norton-healthcare-network-update/

[6] https://regmedia.co.uk/2023/12/11/maine_ag_norton_healthcare_breach_disclosure.pdf

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXeUmrQvEtNZ7GcdZQSmzAAAAAM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.redpacketsecurity.com/alphv-ransomware-victim-norton-healthcare/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXeUmrQvEtNZ7GcdZQSmzAAAAAM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2023/10/25/canadian_hospitals_spamoflague/

[11] https://www.theregister.com/2023/06/22/blackcat_ransomware_plastic_surgery_clinic/

[12] https://www.theregister.com/2023/12/05/alphvblackcat_shakes_up_tactics_again/

[13] https://www.theregister.com/2023/12/02/ransomware_infection_credit_unions/

[14] https://www.theregister.com/2023/06/22/blackcat_ransomware_plastic_surgery_clinic/

[15] https://www.theregister.com/2023/10/25/canadian_hospitals_spamoflague/

[16] https://www.theregister.com/2020/09/18/ransomware_germany_hospital/

[17] https://twitter.com/BrettCallow/status/1732795985301241958

[18] https://aspr.hhs.gov/cyber/Documents/Health-Care-Sector-Cybersecurity-Dec2023-508.pdf?

[19] https://whitepapers.theregister.com/



patents?

Bill Neal

How do you infect a patent?

Re: patents?

Will Godfrey

With patience.

Norton

Fruit and Nutcase

Were they using Norton Antivirus by any chance

Clearly the fault of the healthcare provider

Throatwarbler Mangrove

If they don't have the technical expertise to protect their environment from diligent and upstanding ransomware entrepreneurs, the hospitals should go out of business, and their patients should hurry up and die!

Register for discounts/better service? They ask.

ecofeco

All I hear is, "Want to have your data stolen and worse customer service?"

The only disadvantage I see is that it would force everyone to get Perl.
Horrors. :-)
-- Larry Wall in <8854@jpl-devvax.JPL.NASA.GOV>