FBI warns ransomware assault threatens US healthcare system

In a joint alert Wednesday, the FBI and two federal agencies warned that they had credible information of an increased and imminent cybercrime threat to US hospitals and healthcare providers

October 29, 2020 11:38 am | Updated 11:45 am IST - Boston

Picture used for representational purpose only.

Picture used for representational purpose only.

Federal agencies warned that cybercriminals are unleashing a wave of data-scrambling extortion attempts against the US healthcare system designed to lock up hospital information systems, which could hurt patient care just as nationwide cases of COVID-19 are spiking.

In a joint alert Wednesday, the FBI and two federal agencies warned that they had credible information of an increased and imminent cybercrime threat to US hospitals and healthcare providers. The alert said malicious groups are targeting the sector with attacks that produce data theft and disruption of healthcare services.”

The cyberattacks involve ransomware, which scrambles data into gibberish that can only be unlocked with software keys provided once targets pay up. Independent security experts say it has already hobbled at least five US hospitals this week, and could potentially impact hundreds more.

The offensive by a Russian-speaking criminal gang coincides with the US presidential election, although there is no immediate indication they were motivated by anything but profit. We are experiencing the most significant cyber security threat we’ve ever seen in the United States, Charles Carmakal, chief technical officer of the cybersecurity firm Mandiant, said in a statement.

Also read | Cyberattack hobbles major U.S., U.K. hospital chain

Alex Holden, CEO of Hold Security, which has been closely tracking the ransomware in question for more than a year, agreed that the unfolding offensive is unprecedented in magnitude for the U.S. given its timing in the heat of a contentions presidential election and the worst global pandemic in a century.

The federal alert was co-authored by the Department of Homeland Security and the Department of Health and Human Services.

The cybercriminals launching the attacks use a strain of ransomware known as Ryuk, which is seeded through a network of zombie computers called Trickbot that Microsoft began trying to counter earlier in October. U.S. Cyber Command has also reportedly taken action against Trickbot. While Microsoft has had considerable success knocking its command-and-control servers offline through legal action, analysts say criminals have still been finding ways to spread Ryuk.

The U.S. has seen a plague of ransomware over the past 18 months or so, with major cities from Baltimore to Atlanta hit and local governments and schools hit especially hard.

Also read | Microsoft attempts takedown of global criminal botnet

Holden said he alerted federal law enforcement Friday after monitoring infection attempts at a number of hospitals, some of which may have beaten back infections. The FBI did not immediately respond to a request for comment.

He said the group was demanding ransoms well above $10 million per target and that criminals involved on the dark web were discussing plans to try to infect more than 400 hospitals, clinics and other medical facilities.

One of the comments from the bad guys is that they are expecting to cause panic and, no, they are not hitting election systems, Holden said. They are hitting where it hurts even more and they know it. U.S. officials have repeatedly expressed concern about major ransomware attacks affecting the presidential election, even if the criminals are motivated chiefly by profit.

Mandiant’s Carmakal identified the criminal gang as UNC1878, saying it is deliberately targeting and disrupting U.S. hospitals, forcing them to divert patients to other healthcare providers and producing prolonged delays in critical care.

Neither Holden nor Carmakal would identify the affected hospitals. Four healthcare institutions have been reported hit by ransomware so far this week, three belonging to the St. Lawrence County Health System in upstate New York and the Sky Lakes Medical Center in Klamath Falls, Oregon.

Sky Lakes acknowledged the ransomware attack in an online statement, saying it had no evidence that patient information was compromised. It said emergency and urgent care remain available The St. Lawrence system did not immediately return phone calls seeking comment.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.