News: 1707144306

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Lurie Children's Hospital back to pen and paper after cyberattack

(2024/02/05)


For the second time in one week, cybercriminals have targeted a Chicago children's hospital, this time causing significant operational disruption.

Lurie Children's Hospital said it pulled network systems offline as it continues to respond to "a cybersecurity matter" alongside outside experts and law enforcement agencies.

Email, phone, and internet services are unavailable at the hospital, and according to [1]local news , young patients have been unable to attend scheduled appointments for six days and counting.

[2]

The hospital remains open for emergencies but is operating on a first come first served basis, according to other [3]reports .

[4]

[5]

Some patients with scheduled elective surgeries have also had their appointments pushed back or canceled. Others say ultrasound systems were down and prescriptions were being handled using analog, pen-and-paper methods.

Lurie Children's Hospital said in a [6]statement : "As Illinois' leading provider for pediatric care, our overarching priority is to continue providing safe, quality care to our patients and the communities we serve. Lurie Children's is open and providing care to patients with as limited disruption as possible.

[7]

"We are very grateful to our workforce and care providers who are committed to preserving our charitable mission during this time. We recognize the concern and inconvenience the systems outage may cause our patient-families and community providers and are working diligently to resolve this matter as quickly and effectively as possible."

The hospital treats more than 200,000 children a year and is home to the Stanley Manne Children's Research Institute, which is actively researching a range of pediatric illnesses and injuries.

Attribution for the attack hasn't been made, nor has any ransomware or other cybercrime group claimed responsibility for it.

[8]

The incident closely follows another attack at Saint Anthony Hospital, based just 8km (five miles) from Lurie, with the "credit" [9]swiftly claimed by the LockBit ransomware gang.

The attack on Saint Anthony's system began in December 2023 and the hospital only recently disclosed the extent of the damage – data theft but little to no operational downtime or disruption.

It appears the hospital didn't pay the ransom and the stolen data has been published by LockBit, which is entirely unsurprising given the $800,000 ransom the gang set. Even if Saint Anthony Hospital were inclined to pay, which is very much not the officially recommended route to take, given the lofty sum and the fact it's a non-profit, it's unlikely the hospital would be able to pay anyway.

The healthcare sector has [10]long been a primary target for cybercriminals for many reasons, from generally poorer security postures to the operational disruption an attack on a hospital or similar facility can cause, and everything in between.

[11]Alert: This ransomware preys on healthcare orgs via weak-ass VPN servers

[12]Interpol's latest cybercrime intervention dismantles ransomware, banking malware servers

[13]LockBit shows no remorse for ransomware attack on children's hospital

[14]Ransomware payment rates drop to new low – now 'only 29% of victims' fork over cash

When critical services like these are floored, the chances of making a speedy payment to restore access to key systems is, in theory, more likely than a corporate company that has more time to think about a response strategy.

However, according to new rules [15]reportedly set for imminent approval , US hospitals will have to meet certain cybersecurity standards to receive federal funding in a move the government will hope stems the tide on ransomware's targeting of hospitals.

During El Reg's [16]investigation , we were pointed to a December concept paper from the US Department of Health and Human Services' (HHS) cybersecurity strategy. The paper included proposals for enforcing new standards that if met, would offer financial support and incentives for hospitals. ®

Get our [17]Tech Resources



[1] https://www.cbsnews.com/chicago/news/network-outage-at-lurie-childrens-hospital-continues-following-cyber-security-attack/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZcEUOCk7BS90zuXJZOLAVQAAAQo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://abc7chicago.com/lurie-childrens-outage-hospital-luries-my-chart-chicago-hospitals/14378858/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZcEUOCk7BS90zuXJZOLAVQAAAQo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZcEUOCk7BS90zuXJZOLAVQAAAQo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.luriechildrens.org/en/network-outage/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZcEUOCk7BS90zuXJZOLAVQAAAQo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZcEUOCk7BS90zuXJZOLAVQAAAQo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2024/02/01/lockbit_ransomware_attack_hospital/

[10] https://www.theregister.com/2022/10/24/cisa_fbi_daixin_ransomware/

[11] https://www.theregister.com/2022/10/24/cisa_fbi_daixin_ransomware/

[12] https://www.theregister.com/2024/02/02/interpols_latest_cybercrime_intervention_dismantles/

[13] https://www.theregister.com/2024/02/01/lockbit_ransomware_attack_hospital/

[14] https://www.theregister.com/2024/01/31/ransomware_payment_rates_drop/

[15] https://www.theregister.com/2024/01/10/us_hospitals_security_rules/

[16] https://www.theregister.com/2024/01/10/us_hospitals_security_rules/

[17] https://whitepapers.theregister.com/



our overarching priority is to continue providing safe, quality care

Neil Barnes

Finally! A hospital that suffers this sort of abuse that doesn't tell us data security is its highest priority.

(I wouldn't want to suggest that the neanderthals that execute this sort of vandalism should be in need of the hospital's services. Oh no.)

Re: our overarching priority is to continue providing safe, quality care

sitta_europea

Death's too good for them.

RJW

Targeting a hospital - how low can people get?

Mike 137

" During El Reg's investigation, we were pointed to a December concept paper from the US Department of Health and Human Services' (HHS) cybersecurity strategy. [ [1]The paper ] included proposals for enforcing new standards that if met, would offer financial support and incentives for hospitals. "

Unfortunately the four substantive pages of the HHS paper are so 'high level' that they provide no warranty of effective results. What's actually needed is not yet more policy but sufficient local resourcing and expertise to render the targets of attack maximally robust and resilient. As was proven by NotPetya in the UK, health services are typically wide open targets because they are not informed or equipped enough to address the threats realistically.

[1] https://aspr.hhs.gov/cyber/Documents/Health-Care-Sector-Cybersecurity-Dec2023-508.pdf

Love is in the offing. Be affectionate to one who adores you.