HomeSecurityRansomware is responsible for half of data breaches in hospitals

Ransomware is responsible for half of hospital data breaches

Nearly half of data breaches in hospitals and the broader healthcare sector are due to ransomware attacks, a new study reports.

Ransomware gangs add an extra layer of extortion to their attacks. In addition to encrypting networks and demanding millions of dollars in bitcoins to restore them, hackers also steal sensitive information and threaten to publish it if the ransom is not paid.

ransomware

This double blackmail technique is intended as additional leverage to force victims of ransomware attacks to pay the ransom rather than take the time to restore the network itself . For healthcare, the prospect of data being leaked online is particularly troubling, as it can include sensitive private medical data along with other forms of personally identifiable patient information

Some organizations will, therefore, choose to pay the ransom to prevent this from happening.

As a result, ransomware attacks are now responsible for 46% of healthcare, according to analysis by cybersecurity researchers at Tenable. Over 35% of all breaches are linked to ransomware attacks, often resulting in huge financial costs.

One of the key methods for ransomware gangs to gain access to hospital networks is through two VPN found in the Citrix ADC controller, affecting Gateway hosts (CVE-2019-19781) and Pulse Connect Secure (CVE-2019-11510).

Both of these vulnerabilities received the necessary patches in early 2020, but despite this, a large number of organizations have yet to implement the necessary updates.

Exploiting vulnerabilities has allowed ransomware groups to gain a foothold in networks. Of course, they will continue to do so as long as networks have not received the required security updates.

The key to protecting networks from ransomware attacks is to apply released patches, especially those designed to address critical vulnerabilities. And if your organization has applications that no longer receive security updates, researchers recommend replacing that software with an alternative that is still supported.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS