Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

4/30/2020
04:00 PM
50%
50%

Healthcare Targeted By More Attacks But Less Sophistication

An increase in attacks targeting healthcare organizations suggests that perhaps new cybercriminals are getting into the game.

Healthcare organizations are experiencing an increase in probes and fraud attempts against their businesses and suppliers, but the attacks appear not to be very sophisticated, security experts said this week.

Organizations, for example, saw a 30% increase last month in the number of COVID-19-themed phishing sites and lures, but they have not seen a commensurate increase in the number of successful breaches, according to the Healthcare Information Sharing and Analysis Center (H-ISAC). The mix of more but less sophisticated attacks has led to a greater number of investigations – yet about the same number of breaches, says Michael Hamilton, chief information security officer at cybersecurity-response firm CI Security. Half of the company's client base is made up of healthcare firms, he says.

"The downturn in the global economy has likely led some people into cybercrime, so it's not surprising that we are seeing more attacks but not necessarily by more sophisticated actors," he says. "I think there is a reluctance to single out hospitals right now by a lot of the threat actors, however."

Healthcare companies have struggled with securing their networks, and the recent chaos caused by the coronavirus pandemic and managing the response at hospitals and clinics has left cybersecurity as a secondary concern.

More than 80% of healthcare firms, for example, have medical imaging equipment and devices running older, unpatched operating systems, according to Palo Alto Networks

In addition, external indicators of cybersecurity have dropped, according to SecurityScorecard, a cybersecurity ratings firm that attempts to replicate attacker reconnaissance and rate firms on their apparent cybersecurity posture. The cybersecurity score of the Department of Health and Human Services has dropped from 88 last year to 72 this past month. The healthcare industry as a whole has lower scores than other most other industries, says Alex Heid, chief research officer at the company.

"There has not been a lot of movement, either up or down, for the healthcare industry. They pretty consistently have a low score, a C+/B- average," he says.

Because hospitals have had to cancel elective surgeries and turn away many categories of patients, budgets are tight. While some IT workers are often cut during a downturn, cybersecurity teams will likely remain in demand because of the massive changes happening to IT infrastructure, Heid says.

"Any time there are budget cuts due to anything, IT is often the first to go," he says. "[But] I don't think they will because of the work-from-home stuff. The need for cybersecurity during times of panic or crisis [is] always significant."

While some ransomware groups are avoiding attacks against healthcare firms, others are continuing their efforts, with 14% of attacks in the first quarter targeting the healthcare sector. In February, for example, health-administration tool maker NCR Health acknowledged it had been compromised by ransomware.  

Attempts at outright fraud have not abated, says CI Security's Hamilton. Business e-mail compromise and spear-phishing that target accounts payable with invoices have continued unabated, with attackers looking to cash in on the confusion but not disrupt operations in the same way that ransomware does.

"The confusion and the need for immediate procurement is making some health organizations the victim of outright theft," he says. "They know the stuff they need to buy, and they are getting offers on fake invoices. That type of activity has not gone away."

The H-ISAC has warned healthcare organizations that attackers also continue to seek vulnerabilities in common virtual private network (VPN) devices and software from Citrix, Pulse VPN, and Microsoft's Remote Desktop Protocol, says Errol Weiss, chief security officer for the H-ISAC.

"Health-ISAC continues to warn our members about on-going cyber attacks," he says. "We're also working closely with several volunteer information security research and cyberthreat intelligence groups and sharing threat indicators we derive from partnerships with the CTI League and the Cyber Threat Coalition, just to name a few."

While healthcare companies may be prepared for such attacks, hospital suppliers are often vulnerable since their cybersecurity programs lack the maturity of larger firms. 

"The supply chain is an easier mark," Hamilton says. "All the large firms have their shields up at this point. But if you get into a vendor and leverage a position of trust, it's like finding an unlocked window."

One factor in being a target of cybercriminals: The healthcare industry has a reputation for paying ransoms, SecurityScorecard's Heid says. Until the industry commits to not paying ransoms, attackers will continue to target them with ransomware.

"Yes, healthcare companies need to stay up and running and providing services, but when they get hit, they pay," he says. "That's a problem."

Related Content:

A listing of free products and services compiled for Dark Reading by Omdia analysts to help meet the challenges of COVID-19. 

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "Election Security in the Age of Social Distancing."

 

Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/10/2020
Researcher Finds New Office Macro Attacks for MacOS
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/7/2020
Lock-Pickers Face an Uncertain Future Online
Seth Rosenblatt, Contributing Writer,  8/10/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: It's a technique known as breaking out of the sandbox kids.
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-24330
PUBLISHED: 2020-08-13
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed.
CVE-2020-24331
PUBLISHED: 2020-08-13
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (which contains various settings related to this daemon).
CVE-2020-24332
PUBLISHED: 2020-08-13
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack.
CVE-2020-0261
PUBLISHED: 2020-08-13
In C2 flame devices, there is a possible bypass of seccomp due to a missing configuration file. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-14605...
CVE-2020-17498
PUBLISHED: 2020-08-13
In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.