{"id":1863,"date":"2021-05-28T05:28:42","date_gmt":"2021-05-28T12:28:42","guid":{"rendered":"https:\/\/www.ssls.com\/blog\/?p=1863"},"modified":"2021-05-28T05:28:43","modified_gmt":"2021-05-28T12:28:43","slug":"irish-health-system-still-struggling-after-cyber-attack","status":"publish","type":"post","link":"https:\/\/www.ssls.com\/blog\/irish-health-system-still-struggling-after-cyber-attack\/","title":{"rendered":"Irish health system still struggling after cyber&nbsp;attack"},"content":{"rendered":"\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.ssls.com\/blog\/wp-content\/uploads\/SSLs_Blog_Second-Cyber-Attack-on-Health-System-in-Ireland.png\" alt=\"\" class=\"wp-image-1714\"\/><\/figure>\n\n\n\n<p>Following a <a href=\"https:\/\/www.bbc.com\/news\/world-europe-57134916\">massive<\/a> cyberattack targeting Ireland\u2019s health service IT infrastructure across the country nearly two weeks ago, many hospitals are still without computer services. Believed to have been launched by a cybercriminal group known as Wizard Spider, a ransomware tool called Conti was used to attack the Health Service Executive (HSE). It\u2019s the worst cybercrime attack on an Irish state agency to date.&nbsp;<\/p>\n\n\n\n<!--more-->\n\n\n\n<h2 class=\"wp-block-heading\">What happened?<\/h2>\n\n\n\n<p>On May 14, 2021, the HSE\u2019s systems and many hospital servers were targeted by Wizard Spider, encrypting and stealing more than 700GB of data. The <a href=\"https:\/\/abcnews.go.com\/International\/10-days-ransomware-attack-irish-health-system-struggling\/story?id=77876092\">ransomware group claims<\/a> that they had been in the HSE\u2019s systems for two weeks prior to the attack. The group then demanded $20 million in ransom for the data, which the Irish government so far has refused to pay. In the last few days, the hackers have provided a <a href=\"https:\/\/www.bbc.com\/news\/world-europe-57197688\">decryption tool<\/a> to the HSE for free in order to retrieve the medical data; however, they are still adamant about selling or publishing the data if the ransom is not paid.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Service disruptions<\/h2>\n\n\n\n<p>As one might expect, chaos has ensued when it comes to providing medical services. Because of the IT outage, there is strain across the board, especially when it comes to emergency services, CT scans, and x-ray appointments. Because computers are used to control proper dosing, radiation therapy for cancer patients has been chiefly suspended. According to <a href=\"https:\/\/abcnews.go.com\/International\/10-days-ransomware-attack-irish-health-system-struggling\/story?id=77876092\">ABC news<\/a>, lack of access to patient records and medical histories makes it difficult to provide people with the care they need. Furthermore, because of the lack of computer access, labels for samples and blood transfusions need to be written by hand, so doctors worry about the potential for error.<br><\/p>\n\n\n\n<p>Even though a decryption tool has been provided, it will likely be weeks before systems have returned to normal. The <a href=\"https:\/\/www.irishtimes.com\/news\/crime-and-law\/cyberattack-years-of-fraud-extortion-attempts-could-follow-if-hse-data-published-garda%C3%AD-fear-1.4571896\">police<\/a> also fear that people\u2019s personal data could be harvested for years and utilized for criminal scams.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How can such attacks be prevented?<\/h2>\n\n\n\n<p>It has been widely reported that Ireland\u2019s health services were not prepared to handle such a cyberattack, with a <a href=\"https:\/\/www.irishtimes.com\/news\/health\/hse-warned-three-years-ago-about-it-system-weaknesses-1.4569711\">plethora of weaknesses<\/a> apparent across the HSE\u2019s computer systems. Among these was the use of older and legacy systems, including 37,000 computers that still use Windows 7. Windows hasn\u2019t automatically provided security updates for the operating system since January 2020. The HSE, however, denies that Windows 7 was to blame for the incident, and experts have not yet pinpointed the specific cause. <a href=\"https:\/\/www.politico.eu\/article\/irish-hospital-hack-highlights-eus-weak-spots\/\">Experts say<\/a> that this is something that all European countries should be worried about, as Ireland isn\u2019t the only one depending on vulnerable legacy systems for their IT infrastructure.&nbsp;<br><\/p>\n\n\n\n<p>To prevent such attacks on critical infrastructure in the future, agencies using out-of-date and legacy systems will need to give their cyber networks a complete overhaul. While this is a time-consuming and expensive solution, with ransomware attacks on the rise (<a href=\"https:\/\/www.helpnetsecurity.com\/2021\/03\/08\/ransomware-attacks-grew-2020\/\">growing by 150%<\/a> in 2020 alone), it is necessary. The <a href=\"https:\/\/www.europarl.europa.eu\/RegData\/docs_autres_institutions\/commission_europeenne\/com\/2020\/0823\/COM_COM(2020)0823_EN.pdf\">EU thinks<\/a> so too; it\u2019s currently working on a mandate that would require both public and private entities across the union to adhere to a higher level of cybersecurity or face hefty fines.&nbsp;<br><\/p>\n\n\n\n<p>Making sure that staff have adequate training when it comes to social engineering is also important. Conti often gains access to networks via malicious email links, attachments, or stolen Remote Desktop Protocol (RDP) credentials. Therefore, employees knowing how to recognize suspicious or malicious communications is vital for ransomware prevention.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Wrap up<\/h2>\n\n\n\n<p>The attack on Ireland\u2019s healthcare system was devastating, and unfortunately, it\u2019s unlikely to be the last of its kind. Last week the <a href=\"https:\/\/assets.documentcloud.org\/documents\/20785301\/conti-ransomware-attacks-impact-healthcare-and-first-responder-networks-bc-5-20-21.pdf\">FBI issued<\/a> an alert stating that there have been at least 16 Conti ransomware attacks targeting US healthcare and first responder networks, driving home the fact that this is a global issue. They are among 400 organizations worldwide that have been Conti targets over the past year.<br>Hopefully, this incident and the recent <a href=\"https:\/\/www.ssls.com\/blog\/the-ransomware-group-behind-the-colonial-pipeline-attack\/\">Colonial Pipeline<\/a> attack serve as a wake-up call for public and private entities alike regarding up-to-date IT infrastructure. Unfortunately, unless IT systems reflect modern standards, anyone could become a target too.\n\n<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Following a massive cyberattack targeting Ireland\u2019s health service IT infrastructure across the country nearly two weeks ago, many hospitals are still without computer services. Believed to have been launched by a cybercriminal group known as Wizard Spider, a ransomware tool called Conti was used to attack the Health Service Executive (HSE). It\u2019s the worst cybercrime [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1863","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/posts\/1863","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/comments?post=1863"}],"version-history":[{"count":1,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/posts\/1863\/revisions"}],"predecessor-version":[{"id":1864,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/posts\/1863\/revisions\/1864"}],"wp:attachment":[{"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/media?parent=1863"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/categories?post=1863"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/tags?post=1863"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}