Skip to main content

Data Held for Ransom in 70 Countries; Massive Cyber Attack Hits Russia Hard

London: A huge extortion cyberattack hit dozens of nations Friday, holding computer data for ransom at hospitals, telecommunications firms and other companies. The attack appeared to exploit a vulnerability purportedly identified for use by the US National Security Agency and later leaked to the internet.
The attack hit Britain's health service, forcing affected hospitals to close wards and emergency rooms. Related attacks were reported in Spain, Portugal and Russia. Two security firms — Kaspersky Lab and Avast — said they had identified the malware behind the attack in upward of 70 countries, although both said the attack has hit Russia hardest.
The Russian Interior Ministry has confirmed it was hit by the "ransomware" attack, which encrypts data on infected computers and demands payment, usually via digital currency bitcoin, to release it.
Britain's health service was also hit hard Friday as the attack froze computers at hospitals across the country, shutting down wards, closing emergency rooms and bringing medical treatments to a screeching halt.
Hospitals in areas across Britain found themselves without access to their computers or phone systems. Many cancelled all routine procedures and asked patients not to come to the hospitals unless it was an emergency. Some chemotherapy patients were even sent home because their records could not be accessed.
Most of the affected hospitals were in England, but several facilities in Scotland also reported being hit. Doctors' practices and pharmacies reported similar problems.
As similar widespread ransomware attacks were reported in Spain, Romania and elsewhere, experts warned that online extortion attempts by hackers are a growing menace.
Hospitals, with their often outdated IT systems and trove of confidential patient data, are a particularly tempting target.
British Prime Minister Theresa May said there was no evidence that patient data had been compromised in the attack, and that it had not specifically targeted the National Health Service.
"It's an international attack and a number of countries and organizations have been affected," she said.
NHS Digital, which oversees UK hospital cybersecurity, says the attack used the Wanna Decryptor variant of malware, which infects and locks computers while the attackers demand a ransom.
Pictures posted on social media showed screens of NHS computers with images demanding payment of $300 worth of the online currency Bitcoin, saying: "Ooops, your files have been encrypted!"
Alan Woodward, visiting professor of computing at the University of Surrey, said there was evidence the ransomware was spreading using a Microsoft flaw exposed in a recent leak of information from U.S. intelligence agencies.
He said the affected computers likely had not applied the Microsoft patch or were running old operating systems for which no patch was available.
Tom Griffiths, who was at Bart's Hospital in London for chemotherapy treatment, said a nurse showed him her computer screen, which carried an image of a padlock.
"It had a countdown clock ticking down, stating that all data would be deleted unless a payment was received within that timeframe," he said.
NHS Digital said the attack "was not specifically targeted at the NHS and is affecting organizations from across a range of sectors." It initially said 16 NHS organizations had reported being hit, and more reports came in as the day went on.


Source: News18

Comments

Popular posts from this blog

New software continuously scrambles code to foil cyber attacks: Technique sets a deadline on hackers to severely limit chances of success

New software continuously scrambles code to foil cyber attacks: Technique sets a deadline on hackers to severely limit chances of success : As long as humans are writing software, there will be coding mistakes for malicious hackers to exploit. A single bug can open the door to attackers deleting files, copying credit card numbers or carrying out political mischief. A new program called Shuffler tries to preempt such attacks by allowing programs to continuously scramble their code as they run, effectively closing the window of opportunity for an attack.
The board of Snapdeal is expected to meet tomorrow to discuss the potential sale of India's third largest e-commerce firm to larger rival Flipkart. Also, on the agenda will be getting Nexus Venture Partners (NVP), an early investor in Snapdeal, to agree to the sale deal. The seven-member board of Jasper Infotech, which operates Snapdeal, includes representation from investors SoftBank, Kalaari Capital and Nexus Venture Partners (NVP), as well as co-founders Kunal Bahl and Rohit Bansal. The valuation of Snapdeal is believed to be one of the hurdles to the deal, as Kalaari and NVP were not in agreement with the valuation given by SoftBank, which is the largest shareholder in Snapdeal. SoftBank has now succeeded in getting Kalaari (another early-stage investor in Snapdeal) to agree but is yet to get NVP on board for the deal. The sources said once NVP agrees, the deal with Flipkart could be announced in a matter of weeks. The deal with Flipkart, if it happens, would