Home Blog Page 165

71% of Professionals Consider Cybersecurity Professionals as Highly Skilled

cybersecurity professionals

A study from ISC², a nonprofit association of cybersecurity professionals, revealed that the admiration towards the cybersecurity profession is increasing among the aspiring security professionals, although 29% of professionals said they are considering a career change from the field.

The study “2020 Cybersecurity Perception” stated that 71% of the non-security professionals admitted that they consider cybersecurity professionals to be smart and technically skilled, with 51% describing it as a field with “the good guys fighting cybercrime” and 69% stated the cybersecurity profession is a good career path. 77% of respondents said cybersecurity was never a part of their formal educational curriculum.

ISC² stated the industry made over 2.8 million skilled cybersecurity professionals. According to the survey findings, based on the responses from 2,500 security professionals working across the U.S. and the U.K., there is a global shortage of 4.07 million cybersecurity professionals.

Other Findings include:

  • In the absence of formal cybersecurity education, perceptions about the industry and the professionals in it are formed primarily through portrayals in TV shows and movies (37% of respondents) or by news coverage of security incidents (31%).
  • 61% of respondents said they believe they would either need to go back to school (26%), earn a certification (22%) or teach themselves new skills (13%) to pursue a career in cybersecurity. 32% of respondents said they believe too much technical knowledge or training would be required.
  • Generation Z (Zoomers) were the least likely demographic group to cast cybersecurity professionals in a positive light. Just 58% view cybersecurity professionals as smart and technically skilled, as opposed to 78% of Baby Boomers. And only 34% of Zoomers consider them the good guys fighting cybercrime, as opposed to 60% of Boomers.
  • The job stability is now the most valued characteristic in a career (61% of respondents), followed by ones that offer a “flexible work environment” (57%) and only then, earning potential (56%).

Wesley Simpson, COO of ISC², said, “The cybersecurity profession is still misunderstood by many, and that’s counterproductive to encouraging more people to pursue this rewarding career. The reality of the situation, and what we need to do a better job of publicizing, is that a truly effective cybersecurity workforce requires a broad range of professionals who bring different skill sets to their teams. While technical skills are vital for many roles, we also need individuals with varied backgrounds in areas including communications, risk management, legal, regulatory compliance, process development and more, to bring a well-rounded perspective to cyber defense.”

India: COVID-19 Surveillance Tool Exposes PII of 8 Mn Users

COVID-19 Cyberthreats

A COVID-19 surveillance tool in the Indian state Uttar Pradesh inadvertently exposed the personal information of over eight million people. According to vpnMentor’s researchers, the software named “Surveillance Platform Uttar Pradesh COVID-19” was compromised due to vulnerabilities within the platform; however,  it is now secure after the issue was reported to the authorities.

Multiple Vulnerabilities

The researchers found multiple flaws and lack of basic security protocols in the platform’s infrastructure. There were three significant vulnerabilities, which include:

  1. An unsecured git repository revealing technical information, including passwords to admin accounts on the platform and a SQL data dump.
  2. Access to the platform’s admin dashboard to anyone with the passwords taken from the git repository.
  3. A separate index of CSV files containing daily COVID-19 patient reports – accessible without a password or any other login credentials.

In addition, the researchers also highlighted that the platform’s developers wrongly deployed an unsecured git repository in the source code, database data dumps, passwords, and endpoints. They further left the git repository without password protection, making it accessible for anyone without any login credentials.

“The passwords were listed on the file twice: a hashed version using plain MD5 (without salt), which can be easily cracked using a dictionary, and a plain text version stored side-by-side on a separate column. By having a plain text version of each password, the already weak hashed version was made void and useless. It also appears that no security audits were undertaken on the git repository to review who had access to the data, and to implement robust security protocols, despite numerous parties spread throughout Uttar Pradesh using the surveillance platform to upload data,” vpnMentor said.

Threat to Massive Medical Data

Using malicious vulnerabilities, hackers can take over the platform and can make changes like modifying entries, closing case files, altering patients’ data, modifying test results, sending healthy people to quarantine, removing patients from quarantine early, switching negative test results to positive, and vice versa.

The incident exposed personally identifiable information (PII) of individuals, including admin usernames and passwords, full names, ages, genders, residence addresses, phone numbers, Case IDs, diagnosis, and other medical records.

Personal Data of Over 540,000 Sports Referees Leaked in Failed Ransomware Attack

Ransomware attacks, LockBit Ransomware

ArbiterSports, an official software provider for the NCAA and other sports leagues, revealed that it is a recent victim of a failed ransomware attack, which leaked the personal information of over 540,000 referees and registered members. In an official statement, the company stated that its security teams identified the unauthorized access to certain systems in its network and an attempt to encrypt them.

Foiled Ransomware Attack

Despite detecting and blocking the attackers from encrypting the systems, ArbiterSports stated that hackers pilfered a backup copy of its database. The exposed database contained data from ArbiterGame, ArbiterOne, and ArbiterWorks web applications used by sports leagues to manage their schedules. The compromised data included account usernames and passwords, names, addresses, birth dates,  email addresses, and Social Security numbers. The passwords and Social Security numbers were encrypted in the file, but the unauthorized party was able to decrypt the data.

“Although we were able to prevent devices from being encrypted, the unauthorized party demanded payment in exchange for deleting the files that were obtained. We reached an agreement and obtained confirmation that the unauthorized party deleted the files,” ArbiterSports said.

ArbiterSports notified the law enforcement authorities for further investigation. It is also implementing additional security measures to avert further attacks.

Ransomware: A Lucrative Attack Model

A report published by Coalition, a provider of cyber insurance services in North America, revealed that ransomware incidents accounted for 41% of cyber insurance claims filed in the first six months of 2020. The “H1 2020 Cyber Insurance Claims Report” highlighted that the average ransomware demand increased by 100% from 2019 through 2020. Several organizations stated that ransomware attacks are the most prevalent and destructive of all cyberthreats.

“The severity of ransomware attacks increased by 47%, with a 100% spike from 2019 to Q1 2020. New and malicious strains of ransomware variants such as Maze and DoppelPaymer are leveraged to demand heavy ransom and expose organizational data. An average Maze demand is six times larger than the overall average ransom demand,” the report stated.

Nearly Half the Employees Access Corporate Data on Personal Devices

BYODs

Nearly half the employees access corporate data on their personal devices. According to Trend Micro’s study titled “Head in the Clouds,” 42% of workers in India and 46% of workers in New Zealand use their personal devices to access company data often via services and applications hosted in the cloud. The study showed that home devices and their apps are representing a major weak link in the corporate cybersecurity chain as the lines between work and home life increasingly blur.

At a time when the workforce has been functioning remotely, and attacks against companies and employees with privileged access are on the rise, the trend of employees using personal smartphones, tablets, and laptops may be less secure compared to their corporate equivalents. There are also higher chances that their home network is exposed to vulnerable IoT apps and gadgets.  The report also highlighted that more than a third of 13,000 remote workers surveyed did not have basic password protection on all personal devices.

The study also found that more than half of remote workers have IoT devices connected to their home network, where a sizable number of employees are using lesser-known brands. The problem with lesser-known brands is the vulnerability it poses like unpatched firmware vulnerabilities and insecure logins.

“IoT has empowered simple devices with computing and connectivity, but not necessarily adequate security capabilities”, said Bharat Mistry, Principal Security Strategist at Trend Micro. “They could actually be making hackers’ lives easier by opening backdoors via which they could compromise corporate networks. This threat is amplified as an age of mass remote working blurs the lines between private and company devices, putting both personal and business data in the firing line. Now more than ever, it is important that individuals take responsibility for their cybersecurity and that organizations continue to educate their employees on best practice.”

A Cyberpsychological Issue

According to Dr. Linda K. Kaye, an expert in cyberpsychology, “The fact that so many remote workers use personal devices for accessing corporate data and services suggests that there may be a lack of awareness about the security risks associated with this. Tailored cybersecurity training which recognizes the diversity of different users and their levels of awareness and attitudes around risks would be beneficial to help mitigate any security threats which may derive from these issues.”

More than Half of Singapore Businesses Admit that Cybersecurity is on the Back Burner

Singapore

Remote workforce has made business resilience and operations easier. Businesses have reshaped strategies and are now moving forward like a well-oiled machine. They have tried their best to even secure the extended periphery of cybersecurity to the endpoints of the remote workforce. However, with the battle against COVID-19 not seeming to end any time soon and with many businesses being bootstrapped to continue its operations, reports suggest cybersecurity is going on the back burner instead of being in the driver’s seat.

According to a Barracuda report, Singapore, which ranks in the top 5 for the most prepared in cybersecurity readiness, is also feeling complacent with more than half (51%) of the businesses saying that cybersecurity is now a secondary consideration despite the sharp rise in the number of threats to the remote workforce.

 Key Highlights

  • 43% of Singapore organizations have cut their cybersecurity budgets to save costs as they responded to the pandemic.
  • 39% lacked IT resources or time to upgrade their IT infrastructure in the shift to a remote working model.
  • 48% of respondents said their employees are not properly trained in the cyber risks associated with remote working.
  • 80% plan to provide improved online cybersecurity training and awareness for remote working staff.

Causes for Complacency

The report revealed that more than complacency, it was the shoestring budget that turned out to be the key factor in this case. The findings showed that 43% of Singapore businesses and organizations cut their cybersecurity budgets to save costs while responding to the pandemic. Additionally, 39% of the businesses had inadequate IT resources or little to no time to upgrade their IT infrastructure in the shift to a remote working environment. This highlights that spending on critical controls needs prioritization in the budget discussions held across various board rooms. Organizations can consider consolidating cybersecurity measures by investing in specialized third-party vendors, adopting SaaS-based tools, or assessing how automation could help free budget and resources for security.

The Need for Added Protection

Singapore cybersecurity
Barracuda Report Findings

Employees are often more distracted when working remotely and couple that with a lack of protection on BYOD devices and networks, it makes them more susceptible to cybersecurity attacks. Singapore also reported staggering numbers when it came to reporting cyber incidents. Nearly 51% of the organizations surveyed reported a minimum of at least one data breach or cybersecurity incident since the shifting to remote work. Of these, 51% reported that email phishing attacks was the primary source of attacks, which also emphasizes the need of additional security training for remote workers as human is generally considered as the weaker link in the cybersecurity chain.

Talking about training, 48% of Singapore respondents said their employees are underprepared or not properly trained in the cyber risks associated with remote working. In addition to this, 50% said they lacked confidence in the security of their web applications, which is another major target for malicious actors seeking access to corporate networks and data.

Barracuda Report Findings

The Silver lining

The good news, however, is that most Singapore decision makers are already aware of the problems related to the cybersecurity posture of their remote workforce. This brings clarity and makes the job easier for them to design steps for improvement.

88% of the respondents said that they will need to upgrade their IT infrastructure to improve visibility and productivity, while 85% already knew that cross-industry collaboration was key to improving security standards. Additionally, for being better prepared, 80% respondents were planning to provide improved online cybersecurity training and awareness for remote working staff.

Minnesota Health Care Institutions Affected by Blackbaud Cybersecurity Incident

Minnesota cyberattacks

Blackbaud, a third-party cloud-based service provider, reported a data breach incident in mid-July. However, thousands of Minnesotans are experiencing the ripple effect of the incident as they are receiving the breach notification through email. The letters are being sent to only those individuals whose data, including certain personally identifiable information (PII), fundraiser info, and/or hospital and clinic visit details, have been compromised.

 Key Highlights 

  • Blackbaud security incident affected more than 3 million people around U.S.
  • Certain charities and universities in the U.K. have also been affected by it.
  • An unknown ransomware gang was attempting to encrypt Blackbaud’s systems but were pushed out of the network by Blackbaud’s vigilant security team.
  • The cybercriminals, however, stole an unencrypted data subset from Blackbaud’s systems, which resulted in the massive data breach.

Blackbaud’s Cybersecurity Incident

Blackbaud is particularly known to provide cloud-based fundraising donor management software and database services to thousands of organizations around the world. Its clientele includes some of the top universities, social service nonprofits, health care systems, charitable trusts, and philanthropic organizations of all kinds.

On July 16, 2020, Blackbaud’s internal IT team discovered unauthorized access to its systems. The malicious actor, whose identity is still unknown, reportedly stayed active in Blackbaud’s system between February 7 and May 20, 2020, and may have acquired backups of databases used by its customers. On learning about this incident, Blackbaud informed its customers to stay alert and correspondingly informed the law enforcement authorities about it. On further investigating the incident with the help of cyber forensic experts, Blackbaud’s cybersecurity team linked the malicious actor to a ransomware gang who were attempting to encrypt data on Blackbaud’s system.

Due to the keen observation of some of Blackbaud’s internal cybersecurity personnel, this ransomware attack was averted. However, it was found that certain unencrypted datasets of Blackbaud’s clients were stolen from their systems. This subsequently resulted in one of the biggest data breaches in the state of Minnesota.

Minnesotan Double Whammy

As reported earlier, Blackbaud has a clientele working in health care and non-profit organizations. Thus, two Minnesota based organizations, “Children’s Minnesota Foundation” and “Allina Health” have been severely affected by this data breach. Allina Health has gone forward and informed more than 200,000 of its patients and donors whose data may have been breached in the process. The leaked information of the two organizations potentially contained:

  • Full names
  • Postal addresses
  • Date of birth
  • Appointment dates and doctor names
  • Locations visited, etc.

However, this leaked subset of data did not include:

  • Credit/Debit card information
  • Bank account information
  • Social security numbers (SSN)
  • Any additional medical information, such as diagnosis or treatment plan

Blackbaud takes its commitment to cybersecurity very seriously, and this is evident from how they stopped the ransomware attack before the cybercriminals could encrypt the data. Since it values the privacy of its client’s data, Blackbaud paid the cybercriminal’s demand with a confirmation that the copy they removed from their systems had been destroyed. Blackbaud, with the help of other cybersecurity experts, is now further strengthening their cybersecurity posture to avoid such attacks in the future.

CYBERSEC: Europe’s Most Anticipated Cybersecurity Conference is Here

CYBERSEC Global Cybersecurity Forum 2020

September end will witness one of the most important cybersecurity events in the EU. The 6th edition of the CYBERSEC Global Cybersecurity Forum 2020 will be held from September 28-30, 2020 online. It is one of the most anticipated events covering cybersecurity and cyber policies, and this year, the event goes virtual and is free for everyone. This edition also has a global focus – speakers and attendees from other countries will discuss their cybersecurity challenges.  With an impressive line-up of speakers from NATO, the European Parliament, and other authoritative institutions, the event is well attended every year. This year, the President of the Republic of Estonia, Her Excellency, Kersti Kaljulaid will be one of the principal speakers. One can register for the event here: https://cybersecforum.eu/

This year’s CYBERSEC leitmotif (theme) is: “Together Against Adversarial Internet.” This is aligned to the forum mission which is to enhance cooperation of like-minded countries to secure digital transformation. The event will have four thematic streams (tracks) with prominent figures among the speakers.  The open access to the conference will enable any interested person from all over the world to take part in the event, get insights from big cybersecurity names, and hear about remedies for current cybersecurity dilemmas accelerated by the COVID-19 pandemic.

We live in unprecedented times when the novel Coronavirus pandemic shows clearly the bright and dark sides of digital transformation, as well as the need to cooperate in building a safe cyberspace. “In that light this edition of CYBERSEC will be held under the leitmotif ‘Together Against Adversarial Internet’ – meaning that technologies, although their primary goal is to benefit societies, sometimes play another role as they enable individuals with malicious intent to use them in an adversarial manner, one that hurts rather than benefits societies and economies, and that only an alliance of like-minded partners can stem the rise of malicious actors and authoritarian models of technology deployment as well as secure the cyberspace,” says Izabela Albrycht, Chair of The Kosciuszko Institute and President of the Organizing Committee of the European Cybersecurity Forum – CYBERSEC.

Albrycht is also part of the Advisory Group on emerging and disruptive technologies appointed by NATO Secretary General Jens Stoltenberg.

NATO’s Interest in CYBERSEC

The upcoming CYBERSEC is going to be fundamentally important for the public debate on technology development directions as regards to not only EU but also NATO. Many technologies are dual-use, with both civilian and military applications, hence for some time, NATO has been putting heavy emphasis on establishing policies on innovative solutions, consulting in strategic aspects of disruptive technologies, and trailblazing inventive research. These are the main tasks of the twelve-strong Advisory Group on emerging and disruptive technologies appointed by NATO Secretary-General Jens Stoltenberg; among its members is Izabela Albrycht. In NATO, the person responsible for this process is Deputy Secretary-General of NATO Mircea Geoană, who along with CYBERSEC Chair will be one of the main guests to inaugurate this year’s conference.

Conference Streams

Mirroring past editions, this year’s CYBERSEC will be composed of four thematic streams/tracks. The first one, the State Stream, will focus on the multi-faceted problem of how tech should be regulated for it to develop in a secure manner without slowing down its natural progress. Topics in this Stream include global surveillance, digital governance, and decoupling in the digital supply chain.

The second one, the Future Stream, deals with finding a measured approach to emerging and future technologies and the possibilities and challenges they’ll likely bring to the fore. It will tackle important issues such as quantum computing, threats to digital identity, and human-level artificial intelligence.

Next to it comes the Business Stream, focused on the private sector – the main provider of technology and as such remaining on the very frontline of innovation, research, and development. Here the debates will home in on themes such as countering adversity in the data-driven economy, the role of technology providers in ensuring a peaceful internet, COVID-19 redefining critical sectors of economies.

Finally, there’s the Defence Stream focusing on the technological developments of the military sector and its implications for international security. Attendees can expect subjects such as the military use of 5G, information warfare, and cybersecurity of outer space among others to be discussed on this Stream.

Speaker Line-up

On the speaker front, this year CYBERSEC features personalities such as Margrethe Vestager (EVP, European Commission), Mircea Geoană (Deputy Secretary-General, NATO), Sir Julian King (Former European Commissioner for Security Union), Flavio Aggio (Chief Information Security Officer, WHO), Carine Claeys (EU Special Envoy for Space; Head of the Space Task Force, EEAS), Michael Chertoff (Co-Chair, Global Commission on the Stability of Cyberspace; Former US Secretary of Homeland Security), and from Asia and Pacific region: Samir Saran (President, Observer Research Foundation (ORF), India), Abigail Bradshaw (Head, Australian Cyber Security Centre),  Tobias Feakin (Ambassador for Cyber Affairs and Critical Technology, Australia), Magda Chelly (Head, Cyber Risk Consulting Marsh Asia, Founder of WoSEC Singapore, Brand Ambassador of CYBERSEC FORUM 2020), and Shin Oya (Senior Consulting Fellow, Asia Pacific Initiative).

Global Focus

While historically, this conference has been centered on Europe, this year’s event will extend its range to discuss and tackle truly global strategic cybersecurity challenges by including high-profile names from Australia, New Zealand, Japan, South Korea, Taiwan, Singapore, India, South Africa, Israel, and the UAE.

It will be also open and free for everyone interested in broadening their knowledge and getting insights about cybersecurity and how new technologies affect geopolitical shifts and strategic competition between global players. For more information about the CYBERSEC Global 2020 and for the registration process, visit https://cybersecforum.eu

CYBERSEC Through the Years

EUROPEAN CYBERSECURITY FORUM – CYBERSEC is one of the leading cybersecurity conferences in Europe, organized by the Kosciuszko Institute since 2015. Throughout its six years of history, CYBERSEC has partnered with important international institutions such as NATO, European Commission and European Parliament and has organized 11 editions of CYBERSEC Forums in Europe (Warsaw, Kraków, Katowice and Brussels) and in the United States (Washington) including the participation of renowned figures from different walks of life invested in bringing awareness to cyber threats.

It has also been involved in other region-wide group efforts to provide a secure and safe framework to navigate cyberspace, chief among them the Three Seas Initiative. Furthermore, the EUROPEAN CYBERSECURITY FORUM has been an important advocate voice for a secure rollout of the 5G network, knowledge sharing and upholding good practices in the field of data privacy, and promoting respect in the EU for the NIS Directive among other endeavors.

Through the years, CYBERSEC has hosted 748 speakers from more than 45 countries, more than 400 accredited journalists, enjoyed the support of 293 Partners and Patrons and welcomed more than 5580 participants.

CISO MAG is Media Patron for CYBERSEC Global Cybersecurity Forum 2020.

 

 

Dark Web’s End is Near! Sting Operation Leads to Arrest of 179 Illegal Vendors

BigBasket Allegedly Suffers Data Breach, Customer Data on Dark Web for Sale

An international sting operation by the U.S. and the European law enforcement agencies led to the arrest of 179 darknet vendors and seizure of millions of dollars in cash and virtual currencies, weapons, drugs, and other illegal assets. The operation dubbed as “DisrupTor” was performed in collaboration with the judicial agencies of Austria, Germany, the Netherlands, Sweden, Australia, Canada, the U.K., and the U.S.

The Collaborative Effort

According to a statement released by Europol, officials seized over $6.5 million in both cash and virtual currencies, 64 illicit firearms, including 500 kilograms of drugs like fentanyl, oxycodone, hydrocodone, heroin, cocaine, and other addictive substances. The culprits were arrested in the U.S. (121), Germany (42), the Netherlands (8), the U.K. (4), Austria (3), and Sweden (1). The investigations are still underway as they are yet to find the criminals involved in buying and selling illicit goods on dark web forums.

“This operation follows the takedown in May of last year of Wall Street Market, the world’s then second largest illegal online market in the dark web. Led by the German Federal Criminal Police (Bundeskriminalamt) with the support of the Dutch National Police (Politie) Europol, Eurojust and various U.S. government agencies, this takedown provided investigators with quantitative data and materials to identify suspects behind dark web accounts used for illegal activity,” Europol said.

Say No to Dark Web Market

Europol also warned not to buy illegal goods on the dark web, which expose the victims to dangers like:

  • Dangerous illegal drugs such as fentanyl or counterfeit substances could kill you
  • Become a victim of cyber scammers who are only after your money
  • Exposing your device to damaging malware

The agency also stated that they can track illicit transactions of both buyer and seller on the dark web, and individuals who purchased illicit goods from these sites will be at risk of prosecution globally.

“Law enforcement is most effective when working together, and today’s announcement sends a strong message to criminals selling or buying illicit goods on the dark web: the hidden internet is no longer hidden, and your anonymous activity is not anonymous. Law enforcement is committed to tracking down criminals, no matter where they operate – be it on the streets or behind a computer screen,” Europol added.

Cybersecurity vs Remote Work! CISOs Ignore Security Over Remote Working

active directory
active directory

A research from cybersecurity solutions provider Netwrix revealed the responses of several security leaders globally about the current cyberthreat scenario and how the pandemic and remote working conditions changed their security landscape. The research “2020 Cyber Threats Report” revealed that every fourth organization is concerned that they are exposed to more cyberattacks than before the pandemic.

Surprisingly, 85% of CISOs admitted that they had sacrificed cybersecurity due to a sudden shift to remote work conditions. While 63% reported an increase in the number of cyberattacks, 60% said they found new security gaps due to the distributed work environment. Phishing (48%), admin mistakes (27%), and improper data sharing by employees (26%) are reported as the most common cyberthreats since the transition to remote working.

Other findings include:

  • 25% reported suffering a ransomware or other malware attack during the first three months of the pandemic, while 47% were able to spot it in minutes.
  • Though only 14% of organizations encountered data theft by employees, 66% are anxious about this scenario, compared to just over half, pre-pandemic.
  • Supply chain compromises took the longest to detect; 55% needed days, weeks or even months to flag these incidents.
  • 54% of CISOs admit to lacking the visibility needed to ensure proper data protection.
  • 66% of the IT professionals surveyed regularly report to their executive leadership on the state of cybersecurity. The most common measure used is incident statistics; less than a quarter of respondents calculate financial metrics for their security projects.

The research findings are based on the responses from 937 security decision makers working globally.

Steve Dickson, CEO of Netwrix, said, “The broad disruption to businesses and swift transition to work-from-home caused by the pandemic forced many organizations to prioritize service availability over security. Now that we are all more comfortable with the new normal, IT and security pros should re-examine their earlier decisions with the goal of closing security gaps. This requires identifying sensitive information and reducing its exposure, gaining visibility into user activity, and automating change and configuration auditing to ensure rapid incident detection.”

Also Read: 4 Critical Responsibilities of a CISO Post COVID-19

Ransomware Paralyzes a German Hospital; Patient Dies due to Delayed Aid

Health care data breaches

In a first of its kind, a ransomware attack has been directly held responsible for a person’s death. In view of the consequences of the cyberattack, German prosecutor and police have asserted charges of “Negligent Homicide” in the ongoing investigation against ransomware attackers of Düsseldorf University Hospital. As reports suggest, the attack was unintentional and meant for another University. On realization, the ransomware gang provided the decryption key without demanding a ransom, but not before it led to someone’s fatality.

 Key Highlights 

  • On September 10, 2020, University Hospital Düsseldorf (UKD) was hit by a ransomware attack, mistakenly. The attackers were targeting another University with a similar name.
  • Nearly 30 internal servers were affected in this attack, which limited the health care operations of the hospital to an extent that it had to deregister itself from emergency care providers list.
  • A 78-year old lady in need of immediate critical care was asked to be taken to another hospital in Wuppertal, nearly 19 miles (30kms) away. This delay in medical assistance and re-route to another medical facility probably led to her death.

What Happened

On September 11, 2020, a 78-year old lady from Düsseldorf required emergency medical attention as she faced a ruptured aorta. The lady’s medical history was known and stored on the systems of the health care providers at the Düsseldorf University Hospital. However, the University Hospital was under a ransomware attack that locked out their systems while the lady was being transported to the emergency ward. With the entire hospital system being under a lockdown caused by the cyberattack, the emergency responders in the ambulance carrying the patient were told to shift her to another hospital in Wuppertal, nearly 19 miles (30kms) away. With the unavailability of the patient exact records and data, the doctors at Wuppertal could not do much and the lady, unfortunately, breathed her last.

However, the doctors who attended the lady explained that delay in getting critical medical aid was the primary reason behind her unfortunate demise. It was a no brainer to drive so long when a patient was in dire need of emergency services, but the medics were still following their protocols.

Asserting “Negligent Homicide”

Christoph Hebbecker, a cybercrime prosecutor in the German city of Cologne, told the local media that his office was treating this as a case of “Negligent Homicide” against the ransomware attackers and are further investigating into the matter.

Hebbecker said, “An initial suspicion with regard to negligent homicide is justified”. So far, the investigation for attempted blackmail and computer sabotage has been underway. Further, the exact circumstances that led to the woman’s death will be investigated which will help draw conclusive evidence. But if the delay in services is the primary cause of death then the ransomware attackers can very well be charged with negligent homicide.