6.2 C
New York

Ransomware Attacks on Hospitals: CommonSpirit Breached

Published:

Brief definition of Ransomware

Ransomware Attacks are basically a headline in the news or social media feed. Ransomware is a program that restricts access to files (usually by encrypting them) until the victim pays the attacker. Access can also be denied to specific systems. These attacks will be targeted at businesses and individuals alike while they pose a greater threat to some businesses. The overall goal of cybersecurity is protecting information and people. That task becomes increasingly difficult, whether offensive or defensive, when critical infrastructure such as a hospital is targeted. With the many ways malicious attachments and hidden scripts find their way into networks, how can they effectively defend.

What Happened?

This time, the victims were the patients of CommonSpirit Health. Without access to systems, as a result of ransomware, even the most basic tasks become harder or impossible to complete. In this case there was a data breach on locations in Georgia and Tennessee and it is said to have also affected Nebraska. The impacts of this event are still unclear based on information released from the hospital, but it was clear surgeries were rescheduled due to technical concerns and there were delays in scheduled care. Access to patient records is critical piece of data that can be affected, without it how can professionals ensure they administer proper care? The answer to that it is obvious. The greatest danger these type of attacks pose is loss of life. Today, that was not the case, but it will be an ever-growing concern.

An attacker is likely to target a hospital since instead of spending time under negotiation, they will hopefully pay the ransom to save lives. The decision was to not pay the ransom. For attackers this will likely prompt them to release the data onto deep web or dark web platforms. Their network of patients will hopefully be notified of the data released so they can make any needed changes to their personal lives.

The hospital is handling their incident response. More updates coming as the recovery develops and more information is released.

Sk8Fl0 The Engineer
Sk8Fl0 The Engineer
I am an aspiring Information Security professional.

Related articles

Recent articles