Senators Demand Answers from Telehealth Firms on Pixel-Related Data Sharing Practices
A bipartisan group of senators has written to three telehealth companies demanding answers about the use of third-party tracking technologies on their websites and have requested details of the sensitive health data that they share with third parties such as Meta, Google, and social media networks. In the summer of 2022, The Markup/STAT conducted an investigation into the use of tracking technologies on the websites of U.S. hospitals and found that around one-third of the hospitals investigated had these technologies on their websites. Website tracking code could capture and transmit identifiable health information to third parties, which could be further disclosed and used for targeted advertising. In December 2022, a similar investigation was conducted on the use of the code by telehealth companies. The investigation revealed 49 out of the 50 telehealth websites they investigated were sharing consumer data with third parties through pixels and other website tracking technologies, despite the companies maintaining that any information disclosed to them by consumers would be kept...
Warning Issued About North Korean Ransomware Attacks on Healthcare Organizations
A joint cybersecurity advisory has been issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI), Department of Health and Human Services (HHS), and the Republic of Korea’s Defense Security Agency and National Intelligence Service warning of state-sponsored North Korean (DPRK) ransomware attacks on U.S. critical infrastructure organizations. The agencies have gathered increasing evidence that DPRK threat actors are conducting the attacks to obtain ransom payments to support DPRK national-level priorities and objectives, and the U.S. healthcare and public health (HPH) sector is one of the primary targets. “The North Korean actor behind these incidents, best known as Andariel, has been carrying out a targeted global ransomware campaign against hospitals and healthcare providers. Hospitals that are already under enormous pressure have experienced major disruptions, most of which have gone unnoticed to the public,” John Hultquist, Head of Mandiant Intelligence Analysis – Google Cloud,...
What is Medical Identity Theft?
Medical identity theft is the theft or misuse of an individual’s health information to fraudulently obtain treatment, prescription drugs, or medical equipment. Despite significant penalties for those who obtain or disclose health information without authorization, medical identity theft continues to be an issue for individuals, healthcare providers, and health insurance companies. Nobody knows the true scale of medical identity theft. Some sources have tried to compile medical identity theft statistics using a combination of FTC data, reported HIPAA data breaches, and data from the DoJ’s Bureau of Justice Statistics; but, due to underreporting (estimated to be as high as 92%), it is impossible to accurately calculate the prevalence and cost of impermissible uses of PHI by third parties who have acquired an individual’s data without authorization. Additionally, these sources can give a false impression of how medical identity theft occurs. According to a survey conducted by the Ponemon Institute in 2015, only 16% of medical identity theft is attributable to HIPAA data breaches and...
28% BEC Emails are Opened and 15% Get a Reply
Business Email Compromise scams are the biggest cause of losses to cybercrime. Over the past 5 years, more than $43 billion has been lost to the scams, according to the FBI’s Internet Crime Complaint Center (IC3). In its March 2022 report, the FBI said IC3 had received reports of $2.4 billion in losses to BEC attacks in the last year across almost 20,000 reported attacks, and attacks are continuing to increase. According to a new study by Abnormal Security, between H1 and H2 2022, there was an 81% increase in BEC attacks and a 147% increase in BEC attacks on small businesses over that same period. There are no signs of the attacks slowing, and in all likelihood, they will continue to increase. BEC attacks target human weaknesses. The attackers use social engineering techniques to trick employees into making fraudulent wire transfers, changing bank account information for upcoming vendor payments, changing direct deposit information for employees, purchasing gift cards, and disclosing sensitive data. As with phishing attacks, fear and urgency are used to get employees to respond...
RDP and Cloud Databases Most Common Targets of Threat Actors
Malicious actors used a variety of methods to gain initial access to victims’ networks but in 2022, cybercriminal groups appeared to focus on Remote Desktop Protocol and attacking cloud databases, according to cyber insurer Coalition. RDP is one of the most common ways that initial access brokers (IABs) and ransomware gangs gain access to victims’ networks and RDP is by far the most common remote-scanning by malicious actors. RDP scanning traffic was very high in 2022, with data collected from Coalition’s honeypots indicating RDP scans accounted for 37.67% of all detected scans. Whenever a new vulnerability is identified in RDP, scans soar as cybercriminals rush to identify targets that can be attacked. Ransomware continues to be an enormous problem. In 2022, the gangs increasingly targeted cloud databases, especially Elasticsearch and MongoDB databases, a large number of which have been captured by ransomware gangs. The team identified 68,423 hacked MongoDB databases in 2022, and 22,846 Elasticsearch databases that had been ransomed. The number of new software vulnerabilities has...



