{"id":100201,"date":"2020-10-29T10:11:38","date_gmt":"2020-10-29T07:11:38","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/fbi-warns-of-imminent-ransomware-attacks-on-various-hospitals\/"},"modified":"2020-10-29T10:11:38","modified_gmt":"2020-10-29T07:11:38","slug":"fbi-warns-of-imminent-ransomware-attacks-on-various-hospitals","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/fbi-warns-of-imminent-ransomware-attacks-on-various-hospitals\/","title":{"rendered":"#FBI warns of imminent ransomware attacks on various hospitals"},"content":{"rendered":"<p>&#8220;<strong>#FBI warns of imminent ransomware attacks on various hospitals<\/strong>&#8221;<\/p>\n<div>\n                        BOSTON \u2014 Federal agencies warned that cybercriminals are <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-302a\">unleashing a wave of data-scrambling extortion attempts<\/a> against the U.S. healthcare system designed to lock up hospital information systems, which could hurt patient care just as nationwide cases of COVID-19 are spiking.<\/p>\n<p>In a joint alert Wednesday, the FBI and two federal agencies warned that they had \u201ccredible information of an increased and imminent cybercrime threat to U.S. hospitals and healthcare providers.\u201d The alert said malicious groups are targeting the sector with attacks that produce \u201cdata theft and disruption of healthcare services.\u201d<\/p>\n<p>The cyberattacks involve ransomware, which scrambles data into gibberish that can only be unlocked with software keys provided once targets pay up. Independent security experts say it has already hobbled at least five U.S. hospitals this week, and could potentially impact hundreds more.<\/p>\n<p>The offensive by a Russian-speaking criminal gang coincides with the U.S. presidential election, although there is no im<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">media<\/a>te indication they were motivated by anything but profit. \u201cWe are experiencing the most significant cyber security threat we\u2019ve ever seen in the United States,\u201d Charles Carmakal, chief technical officer of the cybersecurity firm Mandiant, said in a statement.<\/p>\n<p>Alex Holden, CEO of Hold Security, which has been closely tracking the ransomware in question for more than a year, agreed that the unfolding offensive is unprecedented in magnitude for the U.S. given its timing in the heat of a contentions presidential election and the worst global pandemic in a century.<\/p>\n<p>The federal alert was co-authored by the Department of Homeland Security and the Department of Health and Human Services.<\/p>\n<p>The cybercriminals launching the attacks use a strain of ransomware known as Ryuk, which is seeded through a network of zombie computers called Trickbot that Microsoft began trying to counter earlier in October. U.S. Cyber Command has also reportedly taken action against Trickbot. While Microsoft has had considerable success knocking its command-and-control servers offline through legal action, analysts say criminals have still been finding ways to spread Ryuk.<\/p>\n<p>The U.S. has seen a plague of ransomware over the past 18 months or so, with major cities from Baltimore to Atlanta hit and local governments and schools hit especially hard.<\/p>\n<p>In September, a ransomware <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/apnews.com\/article\/media-archive-21ebb97dc7b9e2a7c06244069a35b7e6\">attack hobbled all 250 U.S. facilities<\/a> of the hospital chain Universal Health Services, forcing doctors and nurses to rely on paper and pencil for record-keeping and slowing lab work. Employees described chaotic conditions impeding patient care, including mounting emergency room waits and the failure of wireless vital-signs monitoring equipment.<\/p>\n<p>Also in September, the first known fatality related to ransomware <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/apnews.com\/article\/technology-hacking-europe-cf8f8eee1adcec69bcc864f2c4308c94\">occurred in Duesseldorf, Germany<\/a>, when an IT system failure forced a critically ill patient to be routed to a hospital in another city.<\/p>\n<p>Holden said he alerted federal law enforcement Friday after monitoring infection attempts at a number of hospitals, some of which may have beaten back infections. The FBI did not immediately respond to a request for comment.<\/p>\n<p>He said the group was demanding ransoms well above $10 million per target and that criminals involved on the dark web were discussing plans to try to infect more than 400 hospitals, clinics and other medical facilities.<\/p>\n<figure id=\"attachment_16530520\" class=\"wp-caption alignnone aligncenter\"><img class=\"size-nypost-large-desktop-uncropped wp-image-16530520 lazyload\" alt=\"The Federal Bureau of Investigation headquarters building\" width=\"662\" height=\"441\" srcset=\"https:\/\/nypost.com\/wp-content\/uploads\/sites\/2\/2020\/10\/FBI_Headquarters.jpg?quality=90&amp;strip=all&amp;w=300 300w, https:\/\/nypost.com\/wp-content\/uploads\/sites\/2\/2020\/10\/FBI_Headquarters.jpg?quality=90&amp;strip=all&amp;w=640 640w, https:\/\/nypost.com\/wp-content\/uploads\/sites\/2\/2020\/10\/FBI_Headquarters.jpg?quality=90&amp;strip=all&amp;w=1280 1280w, https:\/\/nypost.com\/wp-content\/uploads\/sites\/2\/2020\/10\/FBI_Headquarters.jpg?quality=90&amp;strip=all&amp;w=662 662w, https:\/\/nypost.com\/wp-content\/uploads\/sites\/2\/2020\/10\/FBI_Headquarters.jpg?quality=90&amp;strip=all&amp;w=1324 1324w\" data-sizes=\"(max-width: 640px) 100vw, 662px\"\/><figcaption class=\"wp-caption-text\"><span>The Federal Bureau of Investigation headquarters building<\/span><span class=\"credit\">AP<\/span><\/figcaption><\/figure>\n<p>\u201cOne of the comments from the bad guys is that they are expecting to cause panic and, no, they are not hitting election systems,\u201d Holden said. \u201cThey are hitting where it hurts even more and they know it.\u201d U.S. officials have repeatedly expressed concern about major ransomware attacks affecting the presidential election, even if the criminals are motivated chiefly by profit.<\/p>\n<p>Mandiant\u2019s Carmakal identified the criminal gang as UNC1878, saying \u201cit is deliberately targeting and disrupting U.S. hospitals, forcing them to divert patients to other healthcare providers\u201d and producing prolonged delays in critical care.<br \/>He called the eastern European group \u201cone of the most brazen, heartless, and disruptive threat actors I\u2019ve observed over my career.\u201d<\/p>\n<p>While no one has proven suspected ties between the Russian government and gangs that use the Trickbot platform, Holden said he has \u201cno doubt that the Russian government is aware of this operation \u2014 of terrorism, really.\u201d He said dozens of different criminal groups use Ryuk, paying its architects a cut.<\/p>\n<p>Dmitri Alperovitch, co-founder and former chief technical officer of the cybersecurity firm Crowdstrike, said there are \u201ccertainly lot of connections between Russian cyber criminals and the state,\u201d with Kremlin-employed hackers sometimes moonlighting as cyber criminals.<\/p>\n<p>Neither Holden nor Carmakal would identify the affected hospitals. Four healthcare institutions have been reported hit by ransomware so far this week, three belonging to the St. Lawrence County Health System in upstate New York and the Sky Lakes Medical Center in Klamath Falls, Oregon.<\/p>\n<p>Sky Lakes acknowledged the ransomware attack in an online statement, saying it had no evidence that patient information was compromised. It said emergency and urgent care \u201cremain available\u201d The St. Lawrence system did not immediately return phone calls seeking comment.<\/p>\n<p>Increasingly, ransomware criminals are stealing data from their targets before encrypting networks, using it for extortion. They often sow the malware weeks before activating it, waiting for moments when they believe they can extract the highest payments, said Brett Callow, an analyst at the cybersecurity firm Emsisoft.<\/p>\n<p>A total of 59 U.S. healthcare providers\/systems have been impacted by ransomware in 2020, disrupting patient care at up to 510 facilities, Callow said.<\/p>\n<p>Carmakal said Mandiant had provided Microsoft on Wednesday with as much detail as it could about the threat so it could <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2020\/10\/kegtap-and-singlemalt-with-a-ransomware-chaser.html\">distribute details to its customers<\/a>. A Microsoft spokesman had no immediate comment.\n            <\/div>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/news\/\" target=\"_blank\" rel=\"noopener noreferrer\">News category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/nypost.com\/2020\/10\/29\/fbi-warns-of-imminent-ransomware-attacks-on-various-hospitals\/\" target=\"_blank\" rel=\"noopener noreferrer\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#FBI warns of imminent ransomware attacks on various hospitals&#8221; BOSTON \u2014 Federal agencies warned that cybercriminals are unleashing a wave of data-scrambling extortion attempts against the U.S. healthcare system designed to lock up hospital information systems, which could hurt patient care just as nationwide cases of COVID-19 are spiking. In a joint alert Wednesday, the&#8230;<\/p>\n","protected":false},"author":1,"featured_media":100202,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/nypost.com\/wp-content\/uploads\/sites\/2\/2020\/10\/shutterstock_263241560.jpg?quality=90&strip=all&w=1200","fifu_image_alt":"","footnotes":""},"categories":[70897],"tags":[77574,70375,20101,73014,70286,4975],"class_list":["post-100201","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-10-29-20","tag-cybersecurity","tag-fbi","tag-health-care","tag-microsoft","tag-russia"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/100201","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=100201"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/100201\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/100202"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=100201"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=100201"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=100201"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}