An advisory from the US Department of Homeland Security (DHS) Cybersecurity, the Infrastructure Security Agency (CISA) and the UK”s National Cyber Security Centre (NCSC) warns of a coordinated attack against the healthcare industry and other essential services.
Advanced Persistent Threat (APT) groups are targeting numerous organizations, including healthcare bodies, pharmaceutical companies, academia, medical research organizations and local governments, especially those involved in national and international COVID-19 response teams.
APTs are usually groups backed by states or an actual state actor seeking to disrupt services, steal data, or spy on the activities of companies and even countries. Healthcare organizations are often hit because they host valuable health-related data. The pandemic makes them a prime target because APTs try to obtain information for domestic research into COVID-19-related medicine.
“These organizations” global reach and international supply chains increase exposure to malicious cyber actors,” reads the advisory. “Actors view supply chains as a weak link that they can exploit to obtain access to better-protected targets. Many supply chain elements have also been affected by the shift to remote working and the new vulnerabilities that have resulted.”
One method used in these attacks is called password spraying, in which bad actors try a brute force attack using common passwords. Since one of the most significant security issues consists of people who choose ridiculously easy passwords or reuse the same password on multiple services, the technique usually yields results.
Even if a single password works in an organization, it”s enough, especially for APT groups who are much more prepared than regular hackers. They can compromise the network, move laterally inside the company or institution if necessary, and access other credentials.
CISA and NCSC say that, as long the COVID-19 pandemic continues, any organization in the healthcare industry will carry extra risk. The two government institutions also presented several possible mitigations:
tags
Silviu is a seasoned writer who followed the technology world for almost two decades, covering topics ranging from software to hardware and everything in between.
View all postsNovember 14, 2024
September 06, 2024