Showing posts with label email attack. Show all posts
Showing posts with label email attack. Show all posts

Thursday, April 23, 2020

Beaumont Hospital with more woes




Hospitals have an exceptionally important role in society-to provide medical treatment. If this is not important enough, taxing the staff, budgetary constraints, and operations in general, there is the COVID-19. To add to this mountain of woe is in one instance is Beaumont Hospital announcing a data breach from last year. Beaumont Health is Michigan’s largest healthcare system.

Incident
In May 2019, the Beaumont Health System email system was breached by an unauthorized third party. The attacker accessed several of Beaumont’s employee email accounts. A portion of these held patient data. The health system became aware of the breach on March 29, 2020. The attackers had access from May 23, 2019, through June 3, 2019. The press release and articles do not indicate how this was discovered or the attack vector (e.g. phishing, social engineering, or another tactic).

One question which should be asked is why detecting this takes nearly a year. During the year the 112k+ persons, or approximately 5% of the 2.3m patients the health system has records for, affected by this were living their lives, thinking everything was fine and there were no worries. This has also been estimated at approximately 114k patients. One day, the affected persons then receive a notice of the unauthorized access, the data compromised, and the hospital's regrets. Was the InfoSec team under-staffed or simply the SIEM was not configured to detect this activity?

The health systems investigation was not able to ascertain if any of the data was actually copied or downloaded by the attackers. In retrospect, if you were going to go to the work and resource use to breach a hospital, once you accomplished your goal, you would not simply walk away.

Data
The unauthorized access is problematic on its own level. To add insult to the injury, the data access included the patient’s name, date of birth, diagnosis, procedure, treatment location, treatment type, prescription information, Beaumont patient account number, and medical record numbers.
But wait; there’s more. A portion of this sample, approximately 460 patients, also had their social security numbers, financial account information, health insurance information, and driver’s license or state identification numbers involved with this. The data was held in emails and email attachments.
When we think through this, the data involved may be used in a myriad of ways. This includes taking over the patient’s identity, filing false tax returns, gaining credit cards in their name, etc. Also, the records could be ransom-wared off. This will add the concern to the already stressed population.

Post-Incident
To remediate the issue, Beaumont has taken steps to better their internal processes and procedures to better their cybersecurity stance. Their press release also notes they will be addressing future threats. The health system is also going to provide additional training for the staff.

The health system’s recommendations to the affected parties were to monitor their insurance statements. Granted this is obvious, however, more action on the health system’s part would have been warranted.

History repeats itself
It would be great to say this was a one-off incident and there has never been an issue. Unfortunately, this is not the case. This represents the second breach this year announced. The prior announcement was in January when the health system notified 1,182 patients that a former employee had been accessing the records of patients. These patients had received treatments after automobile accidents. This data was forwarded to a personal injury attorney.

Resources

Ainsworth, A. (2020, April 17). Beaumont health alerts patients that unauthorized third-party accessed emails containing personal information. Retrieved from https://www.clickondetroit.com/news/local/2020/04/17/beaumont-health-alerts-patients-that-unauthorized-third-party-accessed-emails-containing-personal-information/ 

Davis, J. (2020, April 21). Beaumont health reports 2019 data breach impacting 114k patients. Retrieved from https://healthitsecurity.com/news/beaumont-health-reports-2019-data-breach-impacting-114k-patients

Fox2 Detroit. (2020, April 18). Beaumont health says 112k patients were impacted by data breach. Retrieved from https://www.fox2detroit.com/news/beaumont-health-says-112k-patients-were-impacted-by-data-breach

HIPAA Journal. (2020, April 20). Beaumont health notifies 112,000 patients about may 19 data breach. Retrieved from https://www.hipaajournal.com/beaumont-health-notifies-112000-patients-about-may-2019-data-breach/


Stone, J. (2020, April 20). Detroit hospital network says data breach affected more than 100,000 patient accounts. Retrieved from https://www.cyberscoop.com/beaumont-health-data-breach/

Walsh, D. (2020, April 18). Data breach at Beaumont exposes information of 112,000 patients. Retrieved from https://www.modernhealthcare.com/cybersecurity/data-breach-beaumont-exposes-information-112000-patients

WXYZ. (2020, April). Beaumont says data incident impacted 112k people; names, SSNs and more were in emails accessed. Retrieved from https://www.wxyz.com/news/beaumont-says-data-incident-impacted-112k-people-names-ssns-and-more-were-in-emails-accessed

Tuesday, May 7, 2019

Woesnotgone Meadow; May 7, 2019


All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

In the Meadow, our residents generally are healthy. Occasionally, we have an issue when someone gets sick or hurt. Last May, Jerry slipped on ice and fractured his ankle. When these occur, there may be a brief or longer visit at a healthcare facility. These facilities over the last few years have been a target for attackers, as they attempt to breach their system. One such institution is the Roper St. Francis Healthcare facility.

The Roper St. Francis Healthcare facility is based in Charleston, SC. The healthcare facility was targeted for a phishing attack on a rather large scale. The types of attacks have been relatively steady and popular over the last five years. In this case, there were 13 employee email accounts that were successfully compromised. The successful attack was detected on November 30, 2018. In this case, it is fortunate that the hospital’s operations were not affected. Also, the hospital’s electronic medical records (EMR) were not accessed.

Once detected, the hospital responded quickly. One of the first moves was to block access to corporate accounts. They then began the forensic review. The review noted the compromise was open and active from November 1, 2018, through December 1, 2018. The end date is the day after this was discovered. The hospital also contracted with a third party for a thorough forensic review. The third party in-depth review indicated a number of the compromised email accounts did contain confidential data and information. This data included the patient’s name, medical record numbers, health insurance information, and medical record information. For a portion of these, the patient’s social security number and financial information were also exposed.

The affected patients were notified by mail on January 25, 2019. The hospital also posted a notice on its website on January 29, 2019. The affected patients were offered complimentary credit monitoring services. Internally the healthcare facility is strengthening the email cybersecurity and providing continuing education for this type of attack. These steps are prudent and necessary to prevent, as much as possible, for this to occur again.

This successful attack once again shows the weakest link, in general, is the use. There also needs to be better and regular training to watch for this, along with a more robust defense.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.

Resources
Balchunas, C. (2019, February 4). Roper st. francis phishing attack: What did hackers get access to? Retrieved from https://abcnews4.com/news/local/roper-st-francis-phishing-attack

Davis, J. (2019, February 4). Roper st. francis, valley professionals phishing attacks breach patient data. Retrieved from https://healthitsecurity.com/news/roper-at-francis-valley-professionals-phishing-attack-breach-patient-data

Dissent. (2019, February 4). SC: Roper st. francis notifying patients after employee fall for phishing attack. Retrieved from https://www.databreaches.net/sc-roper-st-frances-notifying-partients-after-employees-fall-for-phishing-attack/

HIPAA Journal (2019, February 4). 13 accounts compromised in roper st. francis healthcare phishing attack. Retrieved from https://www.hipaajournal.com/13-accounts-compromised-in-roper-st-francs-healthcare-phishing-attack/

Phillips, P. (2019, January 29). Roper st. francis healthcare notifies patients after employee emails compromised. Retrieved from http:///www.live5news.com/2019/01/29/roper-st-frances-healthcare-notifies-patients-after-employee-emials-compromised/

Staff Report. (2019, February 5). Roper st. frances employee emails compromised. Retrieved from https://charlestonbusiness.com/news/health/75936/

Thursday, January 24, 2019

Woesnotgone Meadow; December 16, 2018

Woesnotgone Meadow
December 16, 2018
#

All is relatively well here at Woesnotgone Meadow, where everyone has above average bandwidth.

In the Meadow, we do business with the town offices. Margie is there to collect our water, sewer, and trash payments with a smile on her face. The collect certain information as part of their standard operating procedure. We have also, unfortunately, become aware of phishing emails. Just last week, Mayor Jerry thought he was receiving an email from his grandson with birthday pictures. It turns out the surprise wasn’t only at the birthday party. After hours of frustration, his computer was back on track.

The town of Christiansburg is set up much like any other town with these services and functioning to collect fees. The town was targetted and was successfully attacked with a phishing campaign. The attack was discovered on October 26, 2018. The attack for this to be successful only took three staff email accounts to be compromised. The phishing emails were sent in May, June, and September 2018. The subject email accounts contained personally identifiable information (PII) for the affected parties.

Not all the residents of the town of Christiansburg were affected. There were 909 residents affected by the compromise. As of November 2018, the town was not aware of the data exfiltrated being fraudulently used. This, however, brings up a good point. The town wouldn’t necessarily know there is an issue. The town does not have access to all 909 person’s credit reports and other areas where the data could be misused. There is also not necessarily a shelf life for the data. This could be used this week, next month, or next year. The data, for the most part, won’t change. The person may move, however, unless they know there is a problem, prior to reporting this the attackers could use their credit card numbers or other pieces of data.

After the attack had been detected, the town contacted law enforcement and reported the compromise. The town also sent letters to the 909 persons affected by the compromise and are paying for the credit monitoring for the affected parties. For the staff, their login information was changed. As a preventive measure, there has also been additional training for the staff. The prior password convention appears to have been weak and has been updated to a more secure format. To test future potential phishing attempts, the town also is conducting their own phishing tests to raise awareness.

Cybersecurity is not merely a session of mental gymnastics after a compromise. This should be regularly scheduled training with lively, relevant material. When the stale recording that is shown year after year is presented, no one truly cares as the complacency grows.

The phishing training continues to be exceptionally important. The ease of use with the attack and success rate make this the attack of choice. These attacks will continue in numbers and depth as they continue to be successful on the many different levels.

Thanks for visiting Woesnotgone Meadow, where the encryption is strong, and the O/Ss are always using the latest version.

Resources
Gangloff, M. (2018, November 30). Christiansburg offers free credit monitoring after data breach. Retrieved from https://www.roanoke.com/news/local/christiansburg/christiansburg-offers-free-credit-monitoring-after-data-breach/

NRV News. (2018). Free credit monitoring after data security incident. Retrieved from https://nrvnews.com/free-credit-monitoring-after-data-security-incident/


Romano, A. (2018, November 29). 900+ residents’ information compromised in town of christiansburg data security breach. Retrieved from https://ww.wdbj7.com/content/news/900-residents-501601722.html