After crippling cancer hospital with ransomware, crims threaten to swat patients
- Reference: 1704491673
- News link: https://www.theregister.co.uk/2024/01/05/swatting_extorion_tactics/
- Source link:
After [1]intruders broke into Seattle's Fred Hutchinson Cancer Center's IT network in November and stole medical records – everything from Social Security numbers to diagnoses and lab results – miscreants threatened to turn on the patients themselves directly.
The idea being, it seems, that those patients and the media coverage from any swatting will put pressure on the US hospital to pay up and end the extortion. Other crews do similar when attacking IT service provider: they don't just extort the suppliers, they also threaten or further extort customers of those providers.
[2]
"Fred Hutchinson Cancer Center was aware of cyber criminals issuing swatting threats and immediately notified the FBI and Seattle police, who notified the local police," a spokesperson told The Register today. "The FBI, as part of its investigation into the cybersecurity incident, also investigated these threats."
[3]
[4]
The cancer center, which operates more than 10 clinics in Washington's Puget Sound region, declined to answer additional comments about the threats.
Another health network in Oklahoma — Integris Health, which operates a network of 15 hospitals and 43 clinics — last month [5]notified patients about a similar "cyber event" in which criminals may have accessed personal data. Shortly after, some of these patients reported [6]receiving emails from miscreants threatening to sell their information on the dark web.
[7]
"As we work with third-party specialists to investigate this matter and determine the scope of affected data and to whom that data relates, we are providing the latest information for patients and the public here," a spokesperson for Integris told The Register .
"As we confirm affected individuals, we are reaching out to them to provide notification and support, including 24 months of access to free credit monitoring and identity protection services. As our investigation into this matter is ongoing, we are unable to provide additional information at this time."
These kind of boilerplate responses may not be as reassuring as some corporate types think. This latest swatting threat raises worrying questions as to how far criminals are willing to go in their pursuit of loot.
[8]
"Ransoms have been allowed to reach lottery jackpot levels, and the predictable upshot is that people are willing to use more and more extreme measures to collect a payout," Emsisoft threat analyst Brett Callow told The Register .
Earlier this week, the security shop called for a complete [9]ban on ransom payments , noting that extortion tactics were becoming more extreme and now include swatting threats.
"Unfortunately, I think it's only a matter of time before cybercriminals start to use real-world violence to support cyber-extortion," Callow said. "Assuming they haven't already, that is."
Sam Rubin, VP of Unit 42 Consulting at Palo Alto Networks, told The Register his team hadn't seen any swatting attempts by extortion crews in 2023, though the shift in tactics seems likely.
"But I'm not surprised at all," he added, about the reports of Seattle cancer patients potentially receiving these types of threats.
"If you look over the past couple of years, we've seen this continuing evolution of escalating extortion tactics," Rubin said. "If you go back in time, it was just encryption."
[10]Formal ban on ransomware payments? Asking orgs nicely to not cough up ain't working
[11]Swatting suspects charged with subverting Ring doorbell cams and calling cops
[12]As lawmakers mull outlawing poor security, what can they really do to tackle online gangs?
[13]Infosec experts divided over 23andMe's 'victim-blaming' stance on data breach
Over the past year, Unit 42 has seen cybercriminals send threatening texts to the spouse of a CEO whose organization was being extorted, Rubin added, again piling on the pressure for payment. The consulting and incident response unit has also witnessed miscreants sending flowers to a victim company's executive team, and issuing ransom demands via printers connected to the affected firm's network.
"We had another one where the victim organization decided not to pay, but then the ransomware actors went on to harass customers of that organization," Rubin said. "They came back to us and said they regretted the decision [not to pay] because of the reputational impact of the threat actor going to their customers."
These criminals, he added, "are trying to change the balance of leverage to force that payment."
Meanwhile, ransomware attacks against critical infrastructure including hospitals become more frequent. Emsisoft reported 46 infections against US hospitals networks last year alone, up from 25 in 2022. In total, at least 141 hospitals were infected, and at least 32 of the 46 networks had data — including protected health information — stolen.
It's bad enough that these attacks have [14]diverted ambulances and postponed critical care for patients, and now the criminals are inflicting even more pain on people. Last year this included [15]leaking breast cancer patients' nudes. Swatting seems to be the next, albeit abhorrent, step. ®
Get our [16]Tech Resources
[1] https://www.fredhutch.org/en/news/releases/2023/12/fred-hutchinson-cancer-center-notifies-patients-of-data-security.html
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZZiKGMPRXf4mTLB9h6uc4QAAAI8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZiKGMPRXf4mTLB9h6uc4QAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZiKGMPRXf4mTLB9h6uc4QAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://integrisok.com/landing/cyber-event/cyber-event-dec-24-comm
[6] https://twitter.com/hackdba/status/1739742242506473965
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZiKGMPRXf4mTLB9h6uc4QAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZiKGMPRXf4mTLB9h6uc4QAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2024/01/03/ban_ransomware_payments/
[10] https://www.theregister.com/2024/01/03/ban_ransomware_payments/
[11] https://www.theregister.com/2022/12/20/ring_swatting_suspects_charged/
[12] https://www.theregister.com/2024/01/04/feds_stole_the_ransomware_limelight/
[13] https://www.theregister.com/2024/01/04/23andme_victim_blaming_breach/
[14] https://www.theregister.com/2022/10/06/commonspirit_health_cyberattack/
[15] https://www.theregister.com/2023/03/15/cancer_lvhn_sues_hospital/
[16] https://whitepapers.theregister.com/
I vehemently disagree.
Broadcast it on PBS, not pay-per-view. Everybody should be able to watch these bastards suffer (and anyway asking for payment just feels really icky).
Otherwise, upvoted and see icon.
Would it not be possible to give a patient list to the police...
...in order that, if a swatting should be attempted (given that it has already been threatened), the police can visit the premises in a slightly less gung ho method on the basis that it may very well be a fake report?
A far better
option would be fining the manufacturers of the software that gets hacked to leak the information.
Eg criminals do the social engineering to get in the front door with 'try this app to clear the error' or some such BS , followed by the malware walking through holes in the software, with the result that the information is stolen.
Maybe forcing software creators to ensure their products are secure before they are deployed would stop 75% of the ransomware issue.
And yes I'm aware of the social engineering attacks that that would not stop (apart for educating users to challenge random callers) and forcing phone companies to use actual caller IDs instead of having the systems where a caller ID can be spoofed (see a BBC news story about that last week). Only then you'll be able to go after the criminals , but seeing as they are from a different country from where the offence takes place , that could be very hard, especially if the country does not care what its citizens get upto on the internet so long as they dont attack victims in their home country.
The baddies are bad, of course, but perhaps it would help everyone if the US police didn't so often take a "Kill them all and let God sort them out" approach to anonymous phone calls. Just a thought.
These ransomware people shoul;d be tried, and painfully tortured to death live on pay-per-view.
For lesser malware, give them 1 day in prison for every PC they infect. Oh you're in prison for 2,456,405? oh well we won't be needing THIS