Security experts are warning organizations in the Health and Public Health (HPH) sector of increased cyberattacks related to the Akira ransomware. At least 81 attacks have been uncovered since the ransomware was first detected in May 2023. It is worth noting that this is the second alert issued by the Department of Health and Human Services in the last 6 months. The latest alert also includes new information about the tactics, techniques, and procedures (TTPs) used by the ransomware gang.

The majority of Akira ransomware victims are located in the United States , primarily in California, Texas, Illinois, and states on the East Coast, especially the Northeast. The group has targeted multiple sectors: materials, manufacturing, goods and services, construction, education, finance, legal, and healthcare.
See also: Akira and 8Base the most "successful" ransomware gangs of 2023
Akira is a ransomware-as-a-service (RaaS) believed to have ties to the Conti ransomware group. Conti was one of the most popular and prolific ransomware groups until internal conversations and the malware's source code were leaked in 2022.
The techniques and tactics used by the Akira ransomware gang (for attacks on healthcare organizations and elsewhere) have several similarities to those of Conti, suggesting that the groups are connected and that Akira is an equally capable threat group. In 2017, another ransomware variant was detected also called Akira, but the latest attacks do not appear to be related.
Initial access to systems is typically gained through compromised credentials (which may have been obtained through spear phishing). In addition, the group exploits vulnerabilities in VPNs and other applications exposed to the internet, especially those that do not have multi-factor authentication enabled. Once initial access is gained, the group creates persistence, uses tools to hide malicious activity, performs network reconnaissance, and moves through the network. It also communicates with the command-and-control center.
See also: Akira ransomware: Cyberattack on Bucks County emergency system
Like most ransomware groups, Akira carries out double-extortion attacks. That is, it steals data from compromised networks and then proceeds to encrypt files. It then asks the victim to pay both to decrypt the data and to prevent the publication of the stolen data.
The warning to healthcare organizations also includes several recommendations for improving security and preventing Akira ransomware attacks.
Preventive measures include:
- Using strong and unique passwords
- Use multi-factor authentication where possible
- Regular updating of systems and applications
- Use of VPN and firewall
- Disabling unused ports that allow remote access
- Remote access log monitoring
- Check domain controllers, active directories, servers and workstations for new accounts
- Checking Task Scheduler for unknown scheduled tasks
- Requirement to use administrative credentials to install software
- Add banners to emails coming from external sources
- Disabling hyperlinks in emails
- Back up important data
- Network segmentation

What are the potential health impacts of Akira Ransomware?
The consequences of Akira ransomware attacks on the healthcare sector can be serious. First, Akira can cause disruption to healthcare services. This can mean that patients will not be able to receive the necessary care, treatments, or tests they need.
See also: Finland: Increased attacks by Akira ransomware
Second, it can cause the loss or destruction of important medical data. This can include patient medical histories, test results, doctors' notes, and other information that is critical to the delivery of healthcare.
Third, it can lead to breaches of patient privacy. If the encrypted data includes sensitive information, such as medical histories, then patients may be exposed to the risk of having their privacy violated.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Finally, Akira ransomware could have a significant financial impact on the healthcare sector. Organizations may be forced to pay ransoms to get their data back, while service disruption and data loss could lead to additional costs.
Source: www.hipaajournal.com
