CommonSpirit Health Issues Update Confirming 164 Facilities Affected by Ransomware Attack
CommonSpirit Health has issued an update about its October 2022 ransomware attack and has confirmed that patients from 164 facilities were affected by the attack and had their sensitive data exposed or stolen. CommonSpirit Health detected the ransomware attack on October 2, 2022, and the forensic investigation revealed unauthorized individuals had access to its systems between September 16, 2022, and October 3, 2022. In December 2022, CommonSpirit Health confirmed that the threat actor responsible for the attack had stolen patient data prior to encrypting files, and said patients of Franciscan Medical Group/Franciscan Health and Virginia Mason Franciscan Health facilities had been affected. Those individuals were notified about the data breach in December. In February 2023, CommonSpirit Health issued a further update confirming the attackers also obtained the data of patients of St. Luke’s Diagnostic Cath Lab, Diagnostic Heart Center in Houston, TX, and sent notifications to those individuals in February. The latest update on the ransomware attack was issued on April 6, 2023, and...
94% of Organizations Experienced a Cyberattack in 2022
Almost all organizations experienced at least one cyberattack in the past 12 months, according to new research published by Sophos in its State of Cybersecurity 2023 Report. The findings come from an independent study of 3,000 leaders with responsibility for cybersecurity across 14 countries, including the United States. 94% of respondents said they had to deal with at least one cyberattack on their organization in the past 12 months. Malicious actors are increasingly using automation and cybercrime-as-a-service offerings to conduct sophisticated cyberattacks at scale, and network defenders are finding it increasingly difficult to defend against these threats. The problem has been compounded by a shortage of expertise due to the global lack of cybersecurity professionals. The extent to which IT teams are having to investigate and respond to potential intrusions is limiting their ability to complete other IT projects and dedicate time to strategic projects, and IT teams are overworked and overwhelmed. The survey confirmed that IT teams feel they are constantly on the back foot and...
Hackers Increasingly Targeting Cloud Apps to Distribute Malware
Hackers are increasingly using cloud apps for malware delivery, according to the latest Netskope Threat Labs Report. Historically, malicious actors have relived on email and malicious URLs for malware delivery and security solutions have been developed to protect against these attack vectors. Secure email gateways can detect and block malicious email attachments and URL filtering blocks access to malicious websites and as defenses against these vectors have improved, threat actors have had to look for alternative ways to deliver their malicious payloads and many are now taking advantage of the increasing popularity of enterprise cloud apps. As is the case with other industries, cloud apps have proven popular in healthcare for improving productivity and supporting a remote workforce. The average enterprise healthcare user interacts with 22 cloud apps a month, with 94% of enterprise healthcare users downloading data from cloud apps each month. The most popular cloud apps in healthcare are OneDrive, Microsoft Teams, SharePoint, and Google Drive, with OneDrive used by 36% of enterprise...
Hacking Incidents Reported by Chippewa County and Frideres Dental
The Chippewa County Human Resources Division in Wisconsin has recently discovered that the laptop computer of an employee has been compromised and 25-35MB of data was stolen from the device, including information protected under HIPAA. Access to the device was gained through a remote access application, which was downloaded to the device on February 28, 2023. An unknown individual then used the application to access the computer. The employee noticed the access on March 1, 2023, and alerted the IT department, which was able to block further access. According to Chippewa County officials, the unauthorized individual had access to the device for approximately 5 minutes, during which time files were exfiltrated. The investigation confirmed that the breach was limited to one device. It is unclear how the remote access application was downloaded to the device, but it is suspected that this was a drive-by download after the employee inadvertently clicked a link in a phishing email or on a website, or via a website pop-up. The files were reviewed, and it was confirmed that 7 of the copied...
KillNet Hacktivist Group Continues to Target U.S. Healthcare Organizations
The pro-Russian hacktivist group KillNet has continued with its attacks on healthcare organizations in the United States in retaliation for U.S. Congress’s support for Ukraine, and on January 28, 2023, the group launched its biggest wave of Distributed Denial of Service (DDoS) attacks to date – a coordinated attack on more than 90 healthcare organizations in 48 U.S. states. 55% of the targets were healthcare systems with at least one hospital and lone hospitals with Level I trauma centers. The increase in activity has prompted the Health Sector Cybersecurity Coordination Center (HC3) to issue a new Analyst Note about the group, which describes its latest activities, the tactics, techniques, and procedures observed in the recent attacks on the healthcare and public health (HPH) sector, and provides recommended mitigations to defend against and reduce the severity of the group’s attacks. The group has been active since at least January 2022 and has been actively targeting countries that have pledged support for Ukraine following the Russian invasion, especially NATO countries....



