DHB attackers likely to threaten to release patient health records, says expert
Wednesday, 19 May 2021
The hackers who have plunged Waikato DHB into chaos are likely to threaten to dump patient information online if a ransom isn’t paid, a cyber security expert has warned.
The DHB switched off its IT systems on Tuesday in response to an apparent ransomware attack.
Brett Callow, a threat analyst at Nelson cyber-security firm Emsisoft, said the hackers’ next step was likely to be to threaten to dump patients' health records online if the DHB did not pay a ransom, which the health board has said it will not do.
Resident Doctors' Association national secretary Dr Deborah Powell told RNZ it was her understanding the ransomware cyber attack was a type of ransomware called Conti.
**READ MORE:
* Waikato DHB patients being sent around the country in wake of cyber attack
* Heading to Waikato Hospital? Here's what you need to know
* Cyber attack at Waikato hospitals: Patients anxiously wait for updates
* Cyber attack: Government not considering making payment of cyber attack ransom an offence - minister
**
Callow said Conti was one of about 30 crime gangs which encrypted and stole data and used the threat of releasing it online as additional leverage to extort payment.
“Should the target not pay, the data is posted on a so-called ‘leak site' in a series of instalments and, unusually, Conti’s site is on both the ‘clear’ and ‘dark’ webs.”
Conti had posted information hacked from about 15 other ransomware victims online on Wednesday, Callow said.
No information from Waikato DHB was included, but Callow said that meant little as ransomware attackers typically did not start posting data “until they feel the target needs a push”.
Conti has been blamed for a major ransomware attack on the Irish health service last week.
A communication purporting to be from the hackers to the Irish health service obtained by US computer security publication Bleeping Computer stated they were seeking a US$19,999,000 (NZ$27.8m) ransom.
Emsisoft said in a blog post that The Fourth District Court of Louisiana and the Scottish Environment Protection Agency were among victims that had information dumped online in the wake of Conti attacks.
The court documents that were publicly released by the hackers included information relating to defendant pleas, witnesses and jurors, it said.
Conti ransomware was designed to disable victims’ security defences and back-ups and spread within an organisation all while under the hackers’ control, Emsisoft said.
“Attackers may be present on the network for days or even weeks before executing the ransomware,” it said.
Credit ratings agency Fitch said a recent proliferation of ransomware attacks underscored how cyber risks were “cutting across sectors and becoming a growing global security and financial threat”.
It cited research suggesting attacks increased 485 per cent last year.
Recent incidents could spur international efforts to help mitigate against attacks, Fitch said.
There have been growing calls from cyber security experts to make paying or facilitating the payment of ransoms illegal and concerns that cyber-insurers may be unintentionally underpinning attackers’ business models.
Fitch noted that insurer Axa announced it would no longer cover ransomware payments for cyber-insurance policies in France and said that might lead other market participants and jurisdictions to follow suit.
British underwriter Beazley has not followed suit but called on the governments to legislate whether such payouts “align with public policy”, Fitch said.