ALL NEWS

FBI warns ransomware assault threatens US health care system

Oct 29, 2020, 3:12 PM

FBI health care...

FILE - In this Nov. 1, 2017, file photo, traffic along Pennsylvania Avenue in Washington streaks past the Federal Bureau of Investigation headquarters building. In an alert Wednesday, Oct. 28, 2020, the FBI and other federal agencies warned that cybercriminals are unleashing a wave of data-scrambling extortion attempts against the U.S. healthcare system that could lock up their information systems just as nationwide cases of COVID-19 are spiking. (AP Photo/J. David Ake, File)

(AP Photo/J. David Ake, File)

BOSTON (AP) — Federal agencies warned cybercriminals are unleashing a wave of data-scrambling extortion attempts against the U.S. health care system designed to lock up hospital information systems, which could hurt patient care just as nationwide cases of COVID-19 are spiking.

In a joint alert Wednesday, the FBI and two federal agencies warned that they had “credible information of an increased and imminent cybercrime threat to U.S. hospitals and healthcare providers.” The alert said malicious groups are targeting the sector with attacks that produce “data theft and disruption of healthcare services.”

The cyberattacks involve ransomware, which scrambles data into gibberish that can only be unlocked with software keys provided once targets pay up. Independent security experts say it has already hobbled at least five U.S. hospitals this week, and could potentially impact hundreds more.

The offensive by a Russian-speaking criminal gang coincides with the U.S. presidential election, although there is no immediate indication they were motivated by anything but profit. “We are experiencing the most significant cybersecurity threat we’ve ever seen in the United States,” Charles Carmakal, chief technical officer of the cybersecurity firm Mandiant, said in a statement.

Alex Holden, CEO of Hold Security, which has been closely tracking the ransomware in question for more than a year, agreed that the unfolding offensive is unprecedented in magnitude for the U.S. given its timing in the heat of a contentious presidential election and the worst global pandemic in a century.

The federal alert was co-authored by the Department of Homeland Security and the Department of Health and Human Services.

The cybercriminals launching the attacks use a strain of ransomware known as Ryuk, which is seeded through a network of zombie computers called Trickbot that Microsoft began trying to counter earlier in October. U.S. Cyber Command has also reportedly taken action against Trickbot. While Microsoft has had considerable success knocking Trickbot’s command-and-control servers offline through legal action, analysts say criminals have still been finding ways to spread Ryuk.

The U.S. has seen a plague of ransomware over the past 18 months or so, with major cities from Baltimore to Atlanta hit and local governments and schools hit especially hard.

In September, a ransomware attack hobbled all 250 U.S. facilities of the hospital chain Universal Health Services, forcing doctors and nurses to rely on paper and pencil for record-keeping and slowing lab work. Employees described chaotic conditions impeding patient care, including mounting emergency room waits and the failure of wireless vital-signs monitoring equipment.

Also in September, the first known fatality related to ransomware occurred in Duesseldorf, Germany, when an IT system failure forced a critically ill patient to be routed to a hospital in another city.

Holden said he alerted federal law enforcement Friday after monitoring infection attempts at a number of hospitals, some of which may have beaten back infections. The FBI did not immediately respond to a request for comment.

He said the group was demanding ransoms well above $10 million per target and that criminals involved on the dark web were discussing plans to try to infect more than 400 hospitals, clinics and other medical facilities.

“One of the comments from the bad guys is that they are expecting to cause panic and, no, they are not hitting election systems,” Holden said. “They are hitting where it hurts even more and they know it.” U.S. officials have repeatedly expressed concern about major ransomware attacks affecting the presidential election, even if the criminals are motivated chiefly by profit.

Mandiant’s Carmakal identified the criminal gang as UNC1878, saying “it is deliberately targeting and disrupting U.S. hospitals, forcing them to divert patients to other healthcare providers” and producing prolonged delays in critical care.

He called the eastern European group “one of most brazen, heartless, and disruptive threat actors I’ve observed over my career.”

While no one has proven suspected ties between the Russian government and gangs that use the Trickbot platform, Holden said he has “no doubt that the Russian government is aware of this operation — of terrorism, really.” He said dozens of different criminal groups use Ryuk, paying its architects a cut.

Dmitri Alperovitch, co-founder and former chief technical officer of the cybersecurity firm Crowdstrike, said there are “certainly lot of connections between Russian cybercriminals and the state,” with Kremlin-employed hackers sometimes moonlighting as cybercriminals.

Neither Holden nor Carmakal would identify the affected hospitals. Four health care institutions have been reported hit by the ransomware so far this week, three belonging to the St. Lawrence Health System in upstate New York and the Sky Lakes Medical Center in Klamath Falls, Oregon.

Sky Lakes acknowledged the ransomware attack in an online statement, saying it had no evidence that patient information was compromised. It said emergency and urgent care “remain available.”

The St. Lawrence system also acknowledged a Tuesday attack involving Ryuk, noting in a statement released Thursday that no patient or employee data appeared to have been accessed or compromised. Matthew Denner, the emergency services director for St. Lawrence County, told the Adirondack Daily Enterprise that the hospital owner instructed the county to divert ambulances from two of the affected hospitals for a few hours Tuesday.

Increasingly, ransomware criminals are stealing data from their targets before encrypting networks, using it for extortion. They often sow the malware weeks before activating it, waiting for moments when they believe they can extract the highest payments, said Brett Callow, an analyst at the cybersecurity firm Emsisoft.

A total of 59 U.S. health care providers or systems have been impacted by ransomware in 2020, disrupting patient care at up to 510 facilities, Callow said.

Carmakal said Mandiant had provided Microsoft on Wednesday with as much detail as it could about the threat so it could distribute details to its customers. A Microsoft spokesman had no immediate comment.
—-
Associated Press writers Eric Tucker in Washington, D.C., Lisa Baumann in Seattle, Deepti Hajela in New York City and Michael Hill in Albany, N.Y. contributed to this report.

We want to hear from you.

Have a story idea or tip? Send it to the KSL NewsRadio team here.

Today’s Top Stories

All News

The OLRGC released an analysis of the expected topics to be discussed during a special session of t...

Simone Seikaly

Extending state flooding emergency, firearm restrictions, among topics for Utah special session

The OLRGC released an analysis of the expected topics to be discussed during a special session of the legislature.

11 months ago

A video recorded by Facebook user Larry Jacquez shows the police response following the shooting in...

Jamiel Lynch, CNN     

At least 3 people killed and 2 officers wounded in a shooting in Farmington, New Mexico, police say

Multiple people were shot and at least three killed in a shooting in Farmington, New Mexico, police said in a Facebook post.

11 months ago

A new release from Intermountain Healthcare shows that younger adults are becoming more susceptible...

Waverly Golden

Younger adults are becoming more susceptible to strokes

A new release from Intermountain Healthcare shows that younger adults are becoming more susceptible to stroke.

11 months ago

If you plan to camp over Memorial Day Weekend, you may want to begin the planning process now....

Allessandra Harris

Camping over Memorial Day Weekend? Plan ahead

If you plan to camp over Memorial Day Weekend, you may want to begin the planning process now.

11 months ago

slcpd on the scene of the deaths...

Josh Ellis

Police: Teen killed by father in murder-suicide in SLC office building

Police responded to the office complex near 3000 S. Highland Drive on Saturday after emergency responders received a call from a community member who reported finding a body.

11 months ago

Melissa Coleman crouches next to her husband, , Brad Coleman, of North Ogden, who sits in a wheelch...

Jenny Carpenter, KSL.com

Young stroke victim survives with quick, lifesaving treatment in northern Utah

After a 36-year-old man had a stroke, he and his wife say to be aware of the signs of stroke and that young people are also at risk.

11 months ago

Sponsored Articles

close up of rose marvel saliva blooms in purple...

Shannon Cavalero

Drought Tolerant Perennials for Utah

The best drought tolerant plants for Utah can handle high elevations, alkaline soils, excessive exposure to wind, and use of secondary water.

Group of cheerful team members high fiving each other...

Visit Bear Lake

How To Plan a Business Retreat in Bear Lake This Spring

Are you wondering how to plan a business retreat this spring? Read our sample itinerary to plan a team getaway to Bear Lake.

Cheerful young woman writing an assignment while sitting at desk between two classmates during clas...

BYU EMBA at the Marriott School of Business

Hear it Firsthand: 6 Students Share Their Executive MBA Experience at BYU’s Marriott School of Business

The Executive MBA program at BYU offers great opportunities. Hear experiences straight from students enrolled in the program.

Skier being towed by a rider on a horse. Skijoring....

Bear Lake Convention and Visitors Bureau

Looking for a New Winter Activity? Try Skijoring in Bear Lake

Skijoring is when someone on skis is pulled by a horse, dog, animal, or motor vehicle. The driver leads the skiers through an obstacle course over jumps, hoops, and gates.

Banner with Cervical Cancer Awareness Realistic Ribbon...

Intermountain Health

Five Common Causes of Cervical Cancer – and What You Can Do to Lower Your Risk

January is National Cervical Cancer Awareness month and cancer experts at Intermountain Health are working to educate women about cervical cancer.

Kid holding a cisco fish at winterfest...

Bear Lake Convention and Visitors Bureau

Get Ready for Fun at the 2023 Bear Lake Monster Winterfest

The Bear Lake Monster Winterfest is an annual weekend event jam-packed full of fun activities the whole family can enjoy.

FBI warns ransomware assault threatens US health care system