Ransomware feared as IT 'issues' force Octapharma Plasma to close 150+ centers
- Reference: 1713479229
- News link: https://www.theregister.co.uk/2024/04/18/ransomware_octapharma_plasma/
- Source link:
"All centers are experiencing network issues and are currently closed," according to a [1]banner across the top of the company's website.
One source familiar with the situation, however, told The Register Octapharma Plasma fell to a [2]BlackSuit ransomware infection on Monday. We're told the downtime stateside will affect supplies of plasma into Octapharma's European operations.
[3]
"If they don't restore the systems, they will need to close their factories in Europe as more than 75 percent of their plasma comes from the US," the source told us. "IT management don't give a s*** about security and they are now learning a lesson."
Frontier cyberattack
Meanwhile, US ISP Frontier's internal systems suffered an outage this week, taking down its support desk, payment systems, and its ability to send out technicians to install and repair subscribers' connections. While the internet provider was silent on the cause and extent of the breakdown, it [4]told the SEC today "a third party had gained unauthorized access to portions of its information technology environment," and the ISP was trying to contain the intrusion.
"The containment measures, which included shutting down certain [parts] of the company's systems, resulted in an operational disruption," the biz admitted. It also said the intruders likely got hold of people's personal information, and it is in the process of recovering from the cyberattack. Again, this may be another ransomware infection.
Octapharma Plasma, which operates more than [5]150 blood plasma donation centers across America and claims to employ more than 3,500 people nationally, did not respond to The Register 's inquiries.
"Further updates on reopening will be sent via email, social media, OctaApp, and our website," Octapharma noted on its website today.
[6]
[7]
Parent company Octapharma Group, which is based in Germany and has operations across 118 countries, [8]boasted operating income of €436 million ($464 million) in 2023, with record-setting sales of €3.266 billion ($3.48 billion).
The criminals broke into the plasma giant's VMware systems before deploying the BlackSuit ransomware, our source claimed.
[9]
BlackSuit is a relatively new strain of ransomware, which [10]shares code with Royal — and may even be a rebrand of that particular crew. And Royal was a successor to Conti, after the notorious Russian crew disappeared in June 2022.
In November, the US Department of Health and Human Services warned
[11]PDF
that BlackSuit was aggressively targeting healthcare and public health organizations using double-extortion tactics: First stealing sensitive files and then encrypting the data on compromised networks before demanding a ransom payment.[12]185K people's sensitive data in the pits after ransomware raid on Cherry Health
[13]Nearly 1M medical records feared stolen from City of Hope cancer centers
[14]Change Healthcare's ransomware attack costs edge toward $1B so far
[15]Ransomware ban backers insist thugs must be cut off from payday
Our source close to the alleged Octapharma infection didn't know if any extortionists had made any ransom demand, or if the company was negotiating with a crew. We're told the FBI has been alerted, and we've asked the federal bureau for comment.
If it does turn out to be ransomware, Octapharma will join a growing list of [16]US hospitals , [17]health centers and [18]medical firms that have been hit so far this year, as criminals increasingly target these critical orgs.
Encrypting hospital and pharmacy systems with malware may prevent patients from accessing life-saving treatments and medications. Plus, patients and donors trust healthcare companies to protect their sensitive medical and financial details, which puts these providers at risk of class-action lawsuits and investigations if they breach that trust and allow protected information to leak.
[19]
All of this means that the healthcare sector, when facing extortion demands, is more likely to pay a ransom. And that makes the entire industry a prime target for financially motivated crime gangs that have been using increasingly [20]vile extorion tactics to force medical facilities to pay up. ®
Speaking of ransomware...
The FBI, CISA, Europol's European Cybercrime Centre, and the Netherlands' National Cyber Security Centre today released an [21]advisory on the Akira ransomware strain. We're told the malware's masterminds get into organizations "mostly using known Cisco vulnerabilities." The government agencies have issued advice and further information on securing networks from the ransomware and detecting intrusions.
Get our [22]Tech Resources
[1] https://www.octapharmaplasma.com/
[2] https://search.theregister.com/?q=BlackSuit
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZiHsX5Bnd8LzynzZ6dIJ@QAAAQU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.sec.gov/Archives/edgar/data/20520/000119312524100764/d784189d8k.htm
[5] https://www.octapharmaplasma.com/plasma-donation-centers/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZiHsX5Bnd8LzynzZ6dIJ@QAAAQU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZiHsX5Bnd8LzynzZ6dIJ@QAAAQU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.octapharma.com/news/corporate-news/2024/financial-review-2023
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZiHsX5Bnd8LzynzZ6dIJ@QAAAQU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2023/11/14/us_confirms_royalblacksuit_ransomware_ties/
[11] https://www.hhs.gov/sites/default/files/blacksuit-ransomware-analyst-note-tlpclear.pdf
[12] https://www.theregister.com/2024/04/18/ransomware_cherry_health/
[13] https://www.theregister.com/2024/04/03/city_of_hope_data_theft/
[14] https://www.theregister.com/2024/04/16/change_healthcares_ransomware_attack_has/
[15] https://www.theregister.com/2024/03/04/experts_echo_calls_for_ransomware/
[16] https://www.theregister.com/2024/04/03/city_of_hope_data_theft/
[17] https://www.theregister.com/2024/04/18/ransomware_cherry_health/
[18] https://www.theregister.com/2024/04/08/change_healthcare_ransomware/
[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZiHsX5Bnd8LzynzZ6dIJ@QAAAQU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[20] https://www.theregister.com/2024/01/05/swatting_extorion_tactics/
[21] https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a
[22] https://whitepapers.theregister.com/
Guessing the ransomware knows not to attack it's bosses in the Kremlin, Beijing, NORK
There may be occasional lapses in IP mappings, etc. We call that "friendly fire."
The biggest problem in the US, at least, is a totally wild-west capitalist system where the biggest Vulture Capitalist can buy multiple health-care facilities and strip them of any costly IT departments that may try to deter these attacks.
I've witnessed two of my health-care providers in the little state of Vermont be rendered helpless by these attacks - in one case causing multi-week denial of services. These small (by international norms) organizations just don't have, and don't want to pay for, the resources to protect themselves.
Pity the small practices/practioners across this poor country (the US).
Pretty clever
Growing evidence that after the US authorities declared that healthcare was an especially important and vulnerable sector on which cyberwarfare would not be tolerated, the attackers understood exactly how valuable and vulnerable the sector was, and focused their efforts on it.
I'm curious at what rate Russian, Chinese, and North Korean organizations, business and government entities included, are victimized by ransomware. Does anyone have any idea? What, pray tell, are we in the west to do about this--accept the ongoing losses as the price of open IT borders?