HomeSecurityCHwapi: Windows BitLocker "hit" the Belgian hospital!

CHwapi: Windows BitLocker "hit" the Belgian hospital!

CHwapi Hospital in Belgium was hit by a cyberattack, with hackers claiming to have encrypted 40 servers and 100TB of data using Windows BitLocker. The cyberattack resulted in the hospital redirecting patients to other hospitals and delaying surgeries. While the hospital’s services are slowly recovering and surgeries have resumed, CHwapi continues to cancel some services and redirect emergencies to other hospitals.

CHwapi: Windows BitLocker "hit" the Belgian hospital!
  • Information sessions for prospective parents cancelled on January 20 and 21
  • Counseling sessions continue
  • Surgeries continued on January 20th
  • Patient data has not been breached
  • The Covid in MR/MRS is not interrupted
  • At present, CHwapi is not accepting emergencies – patients are transferred to other hospitals

According to L'Avenir, CHwapi was attacked on January 17 at 8:46 p.m. when attackers encrypted 80 of its 300 servers, however, the hospital did not receive a ransom demand.

CHwapi: Windows BitLocker "hit" the Belgian hospital!

The hackers, whose identities have not yet been revealed, told BleepingComputer that they used Windows BitLocker to encrypt 40 servers and 100 TB of data. After encrypting the devices, they left ransom notes named ransom.txt on the domain controllers and backup servers. Additionally, the attackers reported the following in an email to BleepingComputer: “We attacked Chwapi Hospital in Belgium 2 days ago and created ransom notes on the servers. However, the IT team did not provide this information to the hospital management. The hospital management issued a press release and said that there is no ransom note, but that is a lie. Something is happening.”

Instead of using a typical ransomware, this hacking group uses off-the-shelf software, such as Windows BitLocker and DiskCryptor, to encrypt files and lock down access to disk partitions with a password. The hackers also pointed out to BleepingComputer that they are not encrypting every device on the network, and are only targeting servers that have a large volume of files, such as file servers and backup servers.

To communicate with victims, the hacking group in question creates ransom notes that contain a Bitmessage ID, which can be used to negotiate ransom payments.

CHwapi: Windows BitLocker "hit" the Belgian hospital!

Furthermore, the group states that it is not part of a Ransomware-as-a-Service (RaaS) service and does not steal or leak data. It is worth mentioning that some ransomware gangs have stated that they will avoid encrypting hospitals and provide free decryptorsif they have been encrypted.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS