Federal agents warned Wednesday that a major ransomware assault is underway against U.S. hospitals, some of which have already been attacked by a shadowy band of cybercriminals.
Ransomware is an increasing threat to U.S. healthcare and has already cost hospitals tens of millions in recent years. A typical attack encrypts important data — such as patient records and billing information — until the hospital agrees to pay an exorbitant sum for ransom, usually in the form of Bitcoin or other digital currency.
Wednesday’s alert came from a joint federal task force that includes the FBI, the U.S. Department of Health and Human Services, and the Cybersecurity and Infrastructure Security Agency (CISA).
Start the day smarter. Get all the news you need in your inbox each morning.
At least five hospitals were hit with the ransomware attacks this week, the federal agencies said.
“CISA, FBI, and HHS have credible information of an increased and imminent cybercrime threat to U.S. hospitals and healthcare providers,” the advisory said. “CISA, FBI, and HHS are sharing this information to provide warning to healthcare providers to ensure that they take timely and reasonable precautions to protect their networks from these threats.”
‘Willing to pay’: Hospitals hit hardest by ransomware attacks, study says
The aggressive offensive by a Russian-speaking criminal gang coincides with the U.S. presidential election, though there was no immediate indication it was motivated by anything but profit.
“We are experiencing the most significant cyber security threat we’ve ever seen in the United States,” Charles Carmakal, chief technical officer of the cybersecurity firm Mandiant, said in a statement. He’s concerned that the group may deploy malware to hundreds of hospitals over the next few weeks.
Ransomware attempts jumped 50% in the last three months, over the first half of 2020, and hospitals and health care organizations were the hardest hit, according to a study earlier this year by Check Point research.
Typical attacks demand several hundred thousand dollars and some have demanded $5 million or more, the research group concluded. Hospitals are often targeted because criminals know they are more likely to pay than other businesses. That’s because hospitals can’t shut down for long without impacting patient care.
In June, the University of California San Francisco disclosed that it paid $1.14 million to ransomware attackers. In Germany, a woman died when a hospital under a ransomware attack couldn’t admit her. Universal Health Services, one of the nation’s largest health providers, was struck last week.
As a result, health care personnel reportedly began keeping records on paper as computer systems began failing over the weekend and some hospitals have sent incoming ambulances to other neighboring hospitals.
The percentage of healthcare organizations impacted by ransomware globally nearly doubled, from 2.3% in the second quarter to 4% in the third quarter. Healthcare was followed by manufacturing, software makers, government/military and insurance and legal firms.
The U.S. saw 313 attacks in the third quarter, compared to 158 in the previous quarter, very closely