It’s been a bad week for public cybersecurity

It has been quite frankly a terrible week for those across the healthcare sector. Multiple different healthcare organizations have suffered ransomware attacks, each with widespread ramifications. This occurs when attackers lock up sensitive data and hold it hostage until the organization pays a ransom.
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has reported a 264% increase in ransomware incidents reported to them over the past five years. With the sheer amount of data that healthcare companies are tasked with collecting and storing, as well as the frequently sensitive nature of this data, this is unsurprising. This data makes healthcare organizations a prime target for extortion, and hackers have absolutely been taking advantage of this.
This has especially been seen in the last week alone, with a number of different healthcare organizations across the world being hit by, or releasing more information about, their ransomware attacks.
Mental health data exposed in NHS ransomware attack
On May 7, NHS Dumfries and Galloway confirmed that a large amount of personally identifying information belonging to both staff and patients had been published to the dark web. This data included the mental health information of children and was leaked following a ransomware attack launched against the organization.
The cyber attack took place on March 15 after a ransomware gang hacked into NHS Dumfries and Galloway’s computer system and stole a large amount of data.
After the attack, hackers began leaking the data on the dark web as “proof” it had been stolen, with a promise that more would be leaked if a ransom was not paid. This has also resulted in children’s mental health data being leaked in an “utterly abhorrent criminal act” in the words of the Chief Executive for NHS Dumfries and Galloway Julie White.
Due to the amount of data stolen, thousands of people could be impacted.
Get the hottest deals available in your inbox plus news, reviews, opinion, analysis and more from the TechRadar team.
Ascension hospital network taken down by cyber attack
In the United States, ransomware also ran riot against healthcare organizations. On May 8, a serious cybersecurity incident impacting the Ascension hospital network was reported.
The hospital’s entire system was allegedly taken down during the incident, suggesting that a ransomware attack was responsible for the disruption. According to those in the hospital at the time of the incident, doctors were using cellphones to communicate with staff and paper charts were being used. These are both tasks usually undertaken by the hospital’s computer network.
Ascension is currently investigating the cyber attack, and has said that some systems continue to be disrupted.
Ransomware gang extorts NRS Healthcare
Another UK-based ransomware attack was that of mobility aid manufacturer NRS Healthcare. This week saw more information about this attack coming to light.
The attack, which took place on March 29, took all of NRS Healthcare’s services offline. Ransomware group RansomHUB took to the dark web to take responsibility for disabling its phone lines, email, and websites. The group also claimed to have stolen 578 GB of data and said that in order to get the de-encryption key and “resolve” the data breach, NRS Healthcare needs to contact them “as soon as possible”.
The information stolen allegedly includes over 600,000 private documents including contracts, accounting documents, and financial reports. While NRS Healthcare currently believes that the information is related only to an internal part of its network, the company did recognize that it is possible that information related to customers could have been copied to the internal part of the network, and therefore accessed by the hackers.
Why have there been so many healthcare ransomware attacks?
Healthcare organizations hold a lot of very important, confidential, and sensitive information. This information can range from private medical conditions like HIV+ status to information on sensitive topics, like abortion and infertility, to confidential information related to criminal cases like domestic or sexual violence.
Beyond this, healthcare organizations collect and hold a lot of personal information from patients, like home and email addresses, phone numbers, and full names, as it helps them provide services to their patients.
The sensitive and private nature of this information, along with the fact that patients will, in general, not want this information exposed to the general public make healthcare organizations a ripe target for hackers. By stealing, encrypting, and threatening to leak it unless the organization pays a ransom, they put healthcare providers in a really tricky situation.
Either they can go against cybersecurity best practices and pay the hackers, for securing the information, or they can not pay and have the data leaked. Of course, there is a third option where the organization pays the hackers, but then the information is leaked regardless—no matter what, these organizations are put in a lose-lose position.
With this being said, this is why implementing good cybersecurity is so important for these healthcare organizations. Take the Change Healthcare cyber attack from February of this year, for example.
Following the attack, it was revealed that the Citrix portal hackers used to infiltrate Change Healthcare’s network did not have multi-factor authentication (MFA) turned on, and that stolen credentials had been used to gain access to the network.
While the hackers may have been able to gain access to United Healthcare’s systems despite this, it could have been the step that slowed them down or alerted the company that they were on the network—potentially mitigating the cyber attack’s impact.
It has been quite frankly a terrible week for those across the healthcare sector. Multiple different healthcare organizations have suffered ransomware attacks, each with widespread ramifications. This occurs when attackers lock up sensitive data and hold it hostage until the organization pays a ransom. The U.S. Department of Health and…
Recent Posts
- FTC Chair praises Justice Thomas as ‘the most important judge of the last 100 years’ for Black History Month
- HP acquires Humane Ai and gives the AI pin a humane death
- DOGE can keep accessing government data for now, judge rules
- Humane’s AI Pin: all the news about the dead AI-powered wearable
- In a test, 2000 people were shown deepfake content, and only two of them managed to get a perfect score
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010