HomeSecurityHealthcare organizations at risk from Akira ransomware

Healthcare organizations at risk from Akira ransomware

Security experts are warning organizations in the Health and Public Health (HPH) sector of increased cyberattacks related to the Akira ransomware. At least 81 attacks have been uncovered since the ransomware was first detected in May 2023. It is worth noting that this is the second alert issued by the Department of Health and Human Services in the last 6 months. The latest alert also includes new information about the tactics, techniques, and procedures (TTPs) used by the ransomware gang.

Akira ransomware health organizations

The majority of Akira ransomware victims are located in the United States , primarily in California, Texas, Illinois, and states on the East Coast, especially the Northeast. The group has targeted multiple sectors: materials, manufacturing, goods and services, construction, education, finance, legal, and healthcare.

See also: Akira and 8Base the most "successful" ransomware gangs of 2023

Akira is a ransomware-as-a-service (RaaS) believed to have ties to the Conti ransomware group. Conti was one of the most popular and prolific ransomware groups until internal conversations and the malware's source code were leaked in 2022.

The techniques and tactics used by the Akira ransomware gang (for attacks on healthcare organizations and elsewhere) have several similarities to those of Conti, suggesting that the groups are connected and that Akira is an equally capable threat group. In 2017, another ransomware variant was detected also called Akira, but the latest attacks do not appear to be related.

Initial access to systems is typically gained through compromised credentials (which may have been obtained through spear phishing). In addition, the group exploits vulnerabilities in VPNs and other applications exposed to the internet, especially those that do not have multi-factor authentication enabled. Once initial access is gained, the group creates persistence, uses tools to hide malicious activity, performs network reconnaissance, and moves through the network. It also communicates with the command-and-control center.

See also: Akira ransomware: Cyberattack on Bucks County emergency system

Like most ransomware groups, Akira carries out double-extortion attacks. That is, it steals data from compromised networks and then proceeds to encrypt files. It then asks the victim to pay both to decrypt the data and to prevent the publication of the stolen data.

The warning to healthcare organizations also includes several recommendations for improving security and preventing Akira ransomware attacks.

Preventive measures include:

  • Using strong and unique passwords
  • Use multi-factor authentication where possible
  • Regular updating of systems and applications
  • Use of VPN and firewall
  • Disabling unused ports that allow remote access
  • Remote access log monitoring
  • Check domain controllers, active directories, servers and workstations for new accounts
  • Checking Task Scheduler for unknown scheduled tasks
  • Requirement to use administrative credentials to install software
  • Add banners to emails coming from external sources
  • Disabling hyperlinks in emails
  • Back up important data
  • Network segmentation
Healthcare organizations at risk from Akira ransomware

What are the potential health impacts of Akira Ransomware?

The consequences of Akira ransomware attacks on the healthcare sector can be serious. First, Akira can cause disruption to healthcare services. This can mean that patients will not be able to receive the necessary care, treatments, or tests they need.

See also: Finland: Increased attacks by Akira ransomware

Second, it can cause the loss or destruction of important medical data. This can include patient medical histories, test results, doctors' notes, and other information that is critical to the delivery of healthcare.

Third, it can lead to breaches of patient privacy. If the encrypted data includes sensitive information, such as medical histories, then patients may be exposed to the risk of having their privacy violated.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Finally, Akira ransomware could have a significant financial impact on the healthcare sector. Organizations may be forced to pay ransoms to get their data back, while service disruption and data loss could lead to additional costs.

Source: www.hipaajournal.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS