US government warns health and pharma companies after series of ransomware attacks – Endpoints News


As ex­perts warn that phar­ma com­pa­nies are in­creas­ing­ly be­ing tar­get­ed for cy­ber­at­tacks, the US gov­ern­ment is pro­vid­ing new de­tails about a se­ries of ran­somware at­tacks that have hit the health sec­tor over the last year.

The at­tacks, us­ing a ran­somware dubbed Maui, are be­lieved to come from North Ko­rea, ac­cord­ing to a joint state­ment by the FBI, De­part­ment of the Trea­sury, and Cy­ber­se­cu­ri­ty and In­fra­struc­ture Se­cu­ri­ty Agency (CISA). Ran­somware is a type of mal­ware that en­crypts files on a de­vice, ren­der­ing the files and the sys­tems that re­ly on them un­us­able. At­tack­ers then de­mand a ran­som in ex­change for de­cryp­tion.

The Maui at­tack­ers like­ly as­sumed health or­ga­ni­za­tions are will­ing to pay the ran­soms be­cause their ser­vices are crit­i­cal, of­fi­cials said — which is why they be­lieve the at­tacks will like­ly con­tin­ue to fo­cus on the sec­tor. The FBI has been re­spond­ing to Maui at­tacks since May 2021.

Charles Frac­chia

While it’s un­clear ex­act­ly which com­pa­nies and or­ga­ni­za­tions have been hit, the fed­er­al agen­cies urged vic­tims to re­port any in­ci­dents to their lo­cal FBI field of­fice or CISA. In these cas­es, at­tack­ers en­crypt­ed servers used for a va­ri­ety of ser­vices, in­clud­ing elec­tron­ic health records, di­ag­nos­tics, imag­ing and in­tranet.

The agen­cies al­so en­cour­aged com­pa­nies to take a few pre­ven­ta­tive mea­sures, in­clud­ing back­ing up da­ta of­fline, en­crypt­ing back­up da­ta, in­stalling a VPN and main­tain­ing a cy­ber in­ci­dent re­sponse plan. That may in­clude train­ing for em­ploy­ees, or phish­ing ex­er­cis­es. And al­ways up­date op­er­at­ing sys­tems as soon as pos­si­ble, they said.

The num­ber of cy­ber­at­tacks in the bio space has sky­rock­et­ed since the start of the pan­dem­ic, ac­cord­ing to Charles Frac­chia, CEO and founder of Bio­Bright. He’s al­so a co-founder of the Bioe­con­o­my In­for­ma­tion Shar­ing and Analy­sis Cen­ter, an in­ter­na­tion­al non­prof­it ad­dress­ing se­cu­ri­ty threats unique to the bioe­con­o­my.

“Vir­tu­al­ly all bio­man­u­fac­tur­ing in­fra­struc­ture in the US can crum­ble overnight if there’s a tar­get­ed at­tack,” he told End­points News back in Jan­u­ary.

Be­tween 2018 and 2021, dig­i­tal risk pro­tec­tion com­pa­ny Con­stel­la de­tect­ed 9,830 breach­es and leaks at the top 20 phar­ma com­pa­nies on the For­tune Glob­al 500 list, which in­cludes J&J, Mer­ck, Pfiz­er and oth­ers.

Mer­ck was hit by a dev­as­tat­ing ran­somware at­tack back in 2017 dubbed Not­Petya, which elim­i­nat­ed years of re­search and crip­pled Gar­dasil 9 pro­duc­tion.

Are com­pa­nies ris­ing to meet the threat?

“I ac­tu­al­ly think that most of the phar­mas are get­ting there,” Er­ic Per­ak­slis, chief sci­ence and dig­i­tal of­fi­cer role at Duke Clin­i­cal Re­search In­sti­tute, re­cent­ly told End­points News. “Do I think they’re meet­ing the threat? No. But I think they’re do­ing a good job try­ing to get there.”



Source link

Ozinize
Logo
Shopping cart