TechCrunch News 2024年12月04日
Ransomware hackers target NHS hospitals with new cyberattacks
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

英国多家国民医疗服务体系(NHS)医院近期遭受勒索软件攻击,包括Alder Hey儿童医院、Wirral大学教学医院等。攻击者窃取了患者数据、捐赠者报告和采购数据,并可能在调查结束前公开这些数据。Alder Hey医院确认攻击者利用一个数字网关服务入侵了系统,也影响了利物浦心脏和胸腔医院和利物浦大学皇家医院。Wirral大学教学医院也遭遇勒索软件攻击,导致医院宣布重大事件,目前部分服务仍在受影响。NHS长期以来都是勒索软件攻击的目标,英国政府已制定了增强网络安全韧性的战略,并计划在2025年引入网络安全与韧性法案,强制报告勒索软件攻击事件。

🦠**多家NHS医院遭受勒索软件攻击:**包括Alder Hey儿童医院、Wirral大学教学医院等,攻击者窃取了患者数据、捐赠者报告和采购数据,并可能公开这些数据。

🏥**Alder Hey医院确认攻击者利用数字网关服务入侵系统:**该服务被多家医院用于访问其系统,导致Alder Hey、利物浦心脏和胸腔医院以及利物浦大学皇家医院的数据受到影响。

🚨**Wirral大学教学医院遭遇勒索软件攻击,宣布重大事件:**部分服务受到影响,紧急治疗优先,但急诊部门和评估区域的等待时间可能延长。

🇬🇧**英国政府制定网络安全战略,计划引入网络安全与韧性法案:**该法案将在2025年引入,强制报告勒索软件攻击事件,旨在增强NHS的网络安全韧性。

⚠️**NHS长期以来都是勒索软件攻击的目标:**此前Synnovis公司遭受攻击导致大量数据泄露,造成服务中断。

Ransomware hackers have continued an assault on National Health Service trusts across the United Kingdom by compromising multiple hospitals, exposing sensitive patient data and disrupting emergency services.

Inc Ransom, a prolific Russia-linked ransomware group that claimed responsibility for an attack on NHS Scotland earlier this year, now claims to have breached the Alder Hey Children’s Hospital Trust, one of Europe’s largest children’s hospitals. 

In a post on its dark web leak site, Inc Ransom claims to have stolen patient records, donor reports, and procurement data spanning between 2018 and 2024 from Alder Hey. Samples of the alleged stolen data, seen by TechCrunch, include records containing sensitive health information on patients, along with personally identifiable information, such as dates of birth and addresses.

In a statement published on Wednesday, Alder Hey — which first confirmed the cybersecurity incident on November 28 — said it had determined that hackers compromised a “digital gateway service” used by several hospitals to access its systems. This gave the hackers access to data belonging to the children’s hospital, along with data from Liverpool Heart and Chest Hospital and Royal Liverpool University Hospital, the statement said.

“The attacker has claimed to have extracted data from impacted systems,” Alder Hey said in its statement on Wednesday. “We are continuing to take this issue very seriously while investigations continue into whether the attacker has obtained confidential data.”

Alder Hey says that its hospital services remain unaffected and continue to run normally, but warned that there was a possibility that the attackers “may publish the data before our investigation is concluded.”

Separately, the Wirral University Teaching Hospital — located just miles from Alder Hey — has also been targeted by a ransomware attack, which last week forced the hospital to declare a “major incident” after shutting down its systems.

Wirral’s teaching hospital is responsible for a group of hospitals across north-west England, including Arrowe Park Hospital, Clatterbridge Hospital, and Wirral Women and Children’s Hospital.

The disruption caused by the cyberattack, which has not yet been claimed by any major ransomware group, is ongoing. In a statement published on its website Wednesday, the Wirral hospital trust said that while it is in the process of restoring its clinical systems, some services will “continue to be affected.”

“Emergency treatment is being prioritized but there are still likely to be longer than usual waiting times in our Emergency Department and assessment areas,” the trust said. “We urge all members of the public to attend the Emergency Department only for genuine emergencies.”

The NHS has long been an attractive target for ransomware hackers. Earlier this year, the health service declared a “critical” incident after a cyberattack on pathology services provider Synnovis led to a massive data breach and months of disruption, including canceled operations and the diversion of emergency patients. The Qilin ransomware gang, which claimed responsibility for the attack, also leaked 400 gigabytes of sensitive data allegedly stolen from Synnovis, including highly sensitive patient details.

The U.K. government has not commented on the attacks, but last year published a five-pillar strategy that aims to make the NHS more resilient to cyberattacks by 2030. This came just months after a cyberattack on Advanced, an IT service provider, that caused widespread disruption to NHS services across the U.K.

The U.K. government has said it will also introduce the Cyber Security and Resilience Bill to parliament in 2025, which will mandate the reporting of ransomware attacks.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

勒索软件 NHS 网络安全 医院 数据泄露
相关文章