The former chief operating officer of cybersecurity firm Securolytics has pleaded guilty to hacking two hospitals . It appears the executive breached the hospitals to boost his company's business

Vikas Singla , who worked for Securolytics, a network security company that provided services to the healthcare industry, admitted to breaching the systems of GMC Northside Hospitals in Duluth and Lawrenceville .
During his attack on September 27, 2018, he disrupted the services healthcare provider's phone and printer from a Hologic R2 Digitizer device, which was connected to a mammography machine at GMC Hospital in Lawrenceville.
See also: Healthcare: Data breaches in the industry have affected 88 million Americans this year
On the same day, Singla used over 200 printers at GMC Hospital in Duluth to print stolen patient information and “WE OWN YOU” messages.
According to the indictment, the Securolytics executive carried out the attacks and then attempted to publicize the matter and the theft of information to generate business for Securolytics.
Singla promoted the GMC hack on Twitter, posting the names, dates of birth and gender of 43 patients whose data had been stolen in the breach. Securolytics also reached out to potential customers after the attack, highlighting the GMC hacking incident via email.
Prosecutors are asking for a stiff sentence
“This cyberattack on a hospital could have devastating consequences, and in addition, personal patient information was compromised,” said Chris Hacker, FBI Atlanta Special Agent in Charge.
“The FBI and our law enforcement partners are committed to holding those who endanger people's health and safety accountable.“.
Singla has been charged with 17 counts of intentional damage to a protected computer and one count of obtaining information from a protected computer. Prosecutors say the defendant's attack on GMC's ASCOM telephone system, printers and digitizer resulted in financial losses of more than $817,000.
See also: NoEscape ransomware: Targets healthcare organizations
The defendant has agreed to pay over $817,000 plus interest in damages to Northside Hospital Gwinnett in Lawrenceville and Ace American Insurance Company.
Prosecutors will recommend a 57-month suspended sentence, including house arrest, as Singla has been diagnosed with “a rare and incurable form of cancer” and “a potentially dangerous vascular condition,” which warrants “house arrest as an alternative to imprisonment.” The judge can impose a maximum sentence of 10 years in prison at his sentencing hearing, scheduled for Feb. 15, 2024.

Attacks on healthcare organizations
The consequences of cyberattacks on hospitals are multiple and serious. One of the main problems is the disruption of health services, as cyberattacks . can disable the IT systems and electronic infrastructure of hospitals. This can lead to postponements and cancellations of appointments, difficulties in providing medical care and even emergency situations where patients may not receive the necessary help in a timely manner
Additionally, cyberattacks can lead to the theft or loss of sensitive medical data. This can include patient, medical reports, prescriptions, and other personal information. The leakage of this information can have serious consequences for patient privacy and security, as well as trust in the healthcare system.
See also: TransForm: Ransomware attack on hospitals affects data of thousands of patients
Cyberattacks can also cause financial losses for hospitals . Service interruptions and appointment postponements can lead to lost revenue.
Finally, there can be serious impacts on the community and society at large. If a hospital is unable to provide effective medical care due to a cyberattack, this can affect the health and well-being of people in the area.
Source: www.bleepingcomputer.com
