As experts warn that pharma companies are increasingly being targeted for cyberattacks, the US government is providing new details about a series of ransomware attacks that have hit the health sector over the last year.
The attacks, using a ransomware dubbed Maui, are believed to come from North Korea, according to a joint statement by the FBI, Department of the Treasury, and Cybersecurity and Infrastructure Security Agency (CISA). Ransomware is a type of malware that encrypts files on a device, rendering the files and the systems that rely on them unusable. Attackers then demand a ransom in exchange for decryption.
The Maui attackers likely assumed health organizations are willing to pay the ransoms because their services are critical, officials said — which is why they believe the attacks will likely continue to focus on the sector. The FBI has been responding to Maui attacks since May 2021.
Charles FracchiaWhile it’s unclear exactly which companies and organizations have been hit, the federal agencies urged victims to report any incidents to their local FBI field office or CISA. In these cases, attackers encrypted servers used for a variety of services, including electronic health records, diagnostics, imaging and intranet.
The agencies also encouraged companies to take a few preventative measures, including backing up data offline, encrypting backup data, installing a VPN and maintaining a cyber incident response plan. That may include training for employees, or phishing exercises. And always update operating systems as soon as possible, they said.
The number of cyberattacks in the bio space has skyrocketed since the start of the pandemic, according to Charles Fracchia, CEO and founder of BioBright. He’s also a co-founder of the Bioeconomy Information Sharing and Analysis Center, an international nonprofit addressing security threats unique to the bioeconomy.
“Virtually all biomanufacturing infrastructure in the US can crumble overnight if there’s a targeted attack,” he told Endpoints News back in January.
Between 2018 and 2021, digital risk protection company Constella detected 9,830 breaches and leaks at the top 20 pharma companies on the Fortune Global 500 list, which includes J&J, Merck, Pfizer and others.
Merck was hit by a devastating ransomware attack back in 2017 dubbed NotPetya, which eliminated years of research and crippled Gardasil 9 production.
Are companies rising to meet the threat?
“I actually think that most of the pharmas are getting there,” Eric Perakslis, chief science and digital officer role at Duke Clinical Research Institute, recently told Endpoints News. “Do I think they’re meeting the threat? No. But I think they’re doing a good job trying to get there.”
