TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

FBI, DHS, HHS Warn of Imminent Ransomware Threat Against U.S. Hospitals

475 pointsby pictureover 4 years ago

34 comments

haswellover 4 years ago
This is not what we need in these final chapters of 2020 with COVID cases spiking.<p>&gt; <i>Charles Carmakal, senior vice president for Mandiant, told Reuters that UNC1878 is one of most brazen, heartless, and disruptive threat actors he’s observed over the course of his career.</i><p>This is what terrorism looks like in 2020. Horrifying, terrifying, disgusting.
评论 #24927420 未加载
评论 #24930806 未加载
评论 #24927538 未加载
评论 #24930280 未加载
评论 #24926548 未加载
评论 #24927727 未加载
评论 #24936291 未加载
评论 #24928820 未加载
评论 #24929156 未加载
评论 #24926808 未加载
评论 #24926667 未加载
ardit33over 4 years ago
It is happening:<p><a href="https:&#x2F;&#x2F;www.bloomberg.com&#x2F;amp&#x2F;news&#x2F;articles&#x2F;2020-10-28&#x2F;u-s-hospitals-hit-by-coordinated-ransomware-attack-firm-says" rel="nofollow">https:&#x2F;&#x2F;www.bloomberg.com&#x2F;amp&#x2F;news&#x2F;articles&#x2F;2020-10-28&#x2F;u-s-h...</a><p>Patients are being turned away: Wyckoff Hospital hit by computer virus<p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;nyc&#x2F;comments&#x2F;jju0rp&#x2F;wyckoff_hospital_hit_by_computer_virus&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;nyc&#x2F;comments&#x2F;jju0rp&#x2F;wyckoff_hospita...</a>
评论 #24930046 未加载
评论 #24927387 未加载
mullingitoverover 4 years ago
Interesting that DHS&#x27;s public twitter has no word of this, and instead is a full-time campaign ad for the border fence.<p>It&#x27;s also ironic that for all the pervasive government surveillance of the internet, this stuff just flies right under the radar. I thought the whole point of this surveillance was for our protection?
评论 #24930232 未加载
评论 #24927010 未加载
blendoover 4 years ago
Bad health IT is a public health issue.<p>Perhaps it’s time for hospitals to regularly report their OS versions and patch levels to our local health departments.
评论 #24927781 未加载
评论 #24926546 未加载
评论 #24926889 未加载
评论 #24926790 未加载
评论 #24926794 未加载
评论 #24927304 未加载
评论 #24926791 未加载
therockspushover 4 years ago
As diabolical as this is, you wouldn&#x27;t really need state level actions to take down hospitals.<p>Anyone who has been to one in the last year, pre-covid even, understands the ferris wheel of nurses and doctors that churn through the butter of what goes on there.<p>These weren&#x27;t exactly hardened targets to begin with.
nomercy400over 4 years ago
Consider a hospital like a person&#x27;s body.<p>If you don&#x27;t nurture a wound, you&#x27;ll get an infection. If you don&#x27;t clean your hands before eating or you eat something foul, you get diarrhea. The outside world is a dangerous place, and if you wish to interact with it, you should have your defences in order and take necessary precautions. And then still bad actors will get through, such as the yearly flu, so you must deal with that as well.<p>You won&#x27;t defeat the outside world with offense, there&#x27;s just too much out there, adapting too fast.
enahs-sfover 4 years ago
I&#x27;m not sure how, but somehow, I suspect that my health insurance premiums are about to increase.
评论 #24926873 未加载
EQYVover 4 years ago
If this attack results in actual loss of life, I firmly believe the US should ensure that there are real-world physical consequences for these criminals. They cannot be described as anything less than the worst humanity has to offer. A failure to respond with meaningful and severe consequences for those responsible (assuming this is attack can be confidently attributed to a particular threat actor) opens the floodgates. Time to find out how seriously the US takes its own cyber doctrine.<p><a href="https:&#x2F;&#x2F;www.reuters.com&#x2F;article&#x2F;us-usa-defense-cybersecurity-idUSTRE7AF02Y20111116" rel="nofollow">https:&#x2F;&#x2F;www.reuters.com&#x2F;article&#x2F;us-usa-defense-cybersecurity...</a>
评论 #24927933 未加载
评论 #24928385 未加载
评论 #24927078 未加载
评论 #24929292 未加载
评论 #24930835 未加载
评论 #24927087 未加载
评论 #24927086 未加载
latchkeyover 4 years ago
<a href="https:&#x2F;&#x2F;www.nytimes.com&#x2F;2020&#x2F;10&#x2F;28&#x2F;us&#x2F;hospitals-cyberattacks-coronavirus.html" rel="nofollow">https:&#x2F;&#x2F;www.nytimes.com&#x2F;2020&#x2F;10&#x2F;28&#x2F;us&#x2F;hospitals-cyberattacks...</a>
评论 #24926959 未加载
ificanhelpover 4 years ago
This is truly appalling per se, even more so during a global pandemic.<p>If I can be of any help to stop this, disrupt these guys or whatever I&#x27;m ready to give a few of my days and nights to it. Contact email in my about.<p>I&#x27;m a professional developper with a dormant interest in ethical hacking. Been following EH courses, done some CTFs ranging from basic web pen testing to crypto and assembly debugging and been reading&#x2F;watching keenly everything I saw on cyber-security in the past 5-6 years.
buzzertover 4 years ago
Mikko Hypponen and F-Secure will get revenge.<p>&gt; Public message to ransomware gangs: Stay the f away from medical organizations. If you target hospital computer systems during the pandemic, we will use all of our resources to hunt you down.<p><a href="https:&#x2F;&#x2F;nitter.net&#x2F;mikko&#x2F;status&#x2F;1240225603565105152?lang=en" rel="nofollow">https:&#x2F;&#x2F;nitter.net&#x2F;mikko&#x2F;status&#x2F;1240225603565105152?lang=en</a>
shostackover 4 years ago
How similar does this sound to the NotPetya &quot;digital nuke&quot; Russia unleashed on Ukraine?<p><a href="https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;notpetya-cyberattack-ukraine-russia-code-crashed-the-world&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;notpetya-cyberattack-ukraine-rus...</a>
评论 #24926441 未加载
评论 #24926695 未加载
评论 #24926443 未加载
aitchnyuover 4 years ago
Is there an analysis of the stack (OS, apps) used by victim orgs and the holes in their systems? I&#x27;m guessing its always EOLed Windows versions.
评论 #24949061 未加载
vmceptionover 4 years ago
That&#x27;s messed up if true, but why would a ransomware operator target them? I mean like, they don&#x27;t <i>really</i> target, they just wait for people to install something right?
评论 #24926649 未加载
评论 #24926574 未加载
评论 #24926718 未加载
评论 #24926489 未加载
评论 #24926533 未加载
LinuxBenderover 4 years ago
Do all these hospitals have backups that ransomware and automation can not tamper with? Is anti-tampering a requirement in their audits, or just detection? Have any hospitals started implementing secured workstations in kiosk mode? i.e. Windows 10 LTSC with all the hardening options enabled and AD permissions locked down and treating workstations as ephemeral devices.
评论 #24930430 未加载
TheBobinatorover 4 years ago
The actors responsable are doing an all out attack to maximize profits as US Large corps and military are currently targeting their networks to prevent election tampering. These botnet networks have prooven difficult to disrupt even fort hem. This is a profit maximization effort for them and probably one they&#x27;ll do right before folding and disappearing as the last time hosptials and police were directly targeted national governments began disappearing the perpitrators.<p>What&#x27;d be heartless is if the malware, such as the ryuk ransomware in December of 2019, had a bug in it that prevented the decryption key from working and all it did was garble and trash data.<p>Be forwarned, a few groups deploying ransomware are on sanctions lists which carries direct liability if you pay them. If you&#x27;re the IT staff, make the CFO\CEO pay them and wash your hands of it.
JohnCClarkeover 4 years ago
InsurTechnix&#x27;s founders experienced the effects of cyber attacks on multiple hospitals at our previous start up. That&#x27;s one of the reasons we founded InsurTechnix.<p>Here&#x27;s an introduction to our ransomware report: <a href="https:&#x2F;&#x2F;youtu.be&#x2F;2yDqp34JN9k" rel="nofollow">https:&#x2F;&#x2F;youtu.be&#x2F;2yDqp34JN9k</a><p>If any hospital CISO and&#x2F;or IT admin would like a three month free trial - even just to get through the current attacks - please reach out.
marketingProover 4 years ago
US hospitals are ripe to attack. They make huge profits and use extremely outdated tech or use new (untested) software.<p>I take this opportunity to complain about regulatory capture and the medical cartels. Their constant irresponsibility (opioid epidemic, coronavirus response) affects everyone. Yet they still are paid more than any other industry.
easton_sover 4 years ago
My local hospital was hit with ransonware. They had backups but it took almost 5 months to get back to normal.
the_resistenceover 4 years ago
The world&#x27;s security services have to put a full court press on this clear and present danger.
IndySunover 4 years ago
Could this be related to repealing ACA in some way? Would information stolen help one side or the other? Or is there no connection? &amp; How would one know anyway?<p>Non-American (but not ignorant of USA) wondering why this is happening now.
ch4s3over 4 years ago
It&#x27;s interesting that this topic was much talked about when I was working with hospitals 3-5 years ago. They&#x27;ve seen it coming, but have largely squandered the opportunity.<p>Most hospitals store their data and run systems on-prem and are hyper-allergic to anything cloud based. They often have sloppy if extant back-up policies, and I&#x27;ve never heard of a hospital practicing a restore from backups. They also all seem to have terrible policies around passwords that cause most of their staff to iterate passwords every few months by simply incrementing a number at the end. You&#x27;re also quite likely to find passwords on post it notes under half the keyboards in a given facility.<p>Security certifications are kind of a joke and mostly conducted by lawyers and compliance officers who have no technical background, let-alone info sec training.<p>TL;DR this has been a ticking time bomb for a decade and everyone involved knew it.
rltover 4 years ago
I assume&#x2F;hope hospitals have contingency plans for if their network goes down?<p>It would certainly make them less efficient and result in more errors, but hopefully they wouldn’t grind to a complete halt.
garfieldnateover 4 years ago
Why are hospital systems connected to the public internet, anyway? Wouldn&#x27;t it make more sense to have all of the life-or-death stuff on its own secure network?
评论 #24940319 未加载
hrgigerover 4 years ago
There is still an opportunity from the lessons learned. You can regulate your hospital systems as you regulate financial institutions and certificate them. I was also thinking a network setup on a sub-pub system separating trusted and untrusted networks using computer vision via optical sensors or camera&amp;monitor in an old fashion using ocr,classification or even barkod &#x2F;optimized qr code that client picks task id and id from queue and shows on a device and server reads via sensor or camera. Maybe problem is not the we are lack of solution but the systems just old.
flattoneover 4 years ago
Is the US ransom-ware-ing Russia?<p>Or anything similar?
评论 #24927276 未加载
jcadamover 4 years ago
Time to de-digitize, BSG-style. Back to paper records for anything remotely sensitive.<p>And no networked computers for processing anything important.
shp0ngleover 4 years ago
Finally a usecase for Bitcoin
milquetoastafover 4 years ago
Wonder if this is related to the recent breach of psychological patient data
yuskiiover 4 years ago
I don&#x27;t see any specific details on this.
评论 #24927851 未加载
评论 #24926890 未加载
Dahoonover 4 years ago
Someone should ransomware Krebs and force him to get a mobile friendly site.
评论 #24926907 未加载
naveen99over 4 years ago
Maybe hospitals should escrow their data with NSA. Append only backups. Get ransomware, restore from NSA backup. Make all that storage capacity useful.
RcouF1uZ4gsCover 4 years ago
The simplest solution is to ban Bitcoin and the other cryptocurrency. Crypto currency is what enables this.
Stierlitzover 4 years ago
Seriously HR admins, if you care anything about your reputation, you should cease re-posting this kind of neocon disinformation.
评论 #24926820 未加载