Read The Times Australia

Daily Bulletin

Australian hospitals are under constant cyber attack. The consequences could be deadly

  • Written by: Paul Haskell-Dowland, Associate Dean (Computing and Security), Edith Cowan University

Last week, the Australian Cyber Security Centre (ACSC) issued warnings to Australian health-care providers that it had observed an increase in cyber incidents targeting the sector.

These attacks seem to be aimed at infiltrating networks and burrowing deep into their infrastructure before deploying further attacks.

The ACSC is tasked with improving Australia’s cyber security posture, and provides advice and support to help ensure Australia is a secure place to live and work. As part of its warning, the ACSC flagged the possibility of “ransomware” being deployed, which could disable critical systems unless a ransom is paid. In a hospital or other health-care facility, this could be a life-threatening situation.

Attacks against the health-care sector are dangerous at any time. But when services are under pressure from COVID-19, and information-sharing (including tools such as contact tracing) is increasingly important, an all-out cyber attack against the health sector could be very damaging.

The current threat

The ACSC guidance identifies two significant threats.

The first is the SDBBot Remote Access Tool (often referred to as a RAT), whereas the second is a ransomware tool named Cl0p. While neither is desirable, the combination of the two is particular concerning in a health-care setting.

SDBBot Remote Access Tool (RAT)

A RAT is a piece of malicious software designed to allow criminals to remotely access and control one or more systems in an organisation. Once run, the SDBBot RAT installs itself, downloads additional components and deploys the remote-access capability.

Once fully installed, criminals will often use a compromised computer to explore other systems – a technique often referred to as “pivoting”. As the criminals move through the network, they often take the opportunity to make copies of sensitive data. This can be a valuable asset to use for coercion, blackmail or even sell through the underground economy.

Cl0p ransomware

Having the SDBBot RAT successfully deployed enables other attacks – one of the most concerning is that of ransomware. While not an inherent feature of SDBBot, a frequent consequence of infection is the subsequent deployment of the Cl0p ransomware.

Ransomware generally encrypts an organisation’s files or data so they are no longer accessible. Recovering the files typically involves paying a ransom, often in Bitcoin or another cryptocurrency.

In October, German company Software AG faced a US$20 million ransom demand after a Cl0p ransomware attack. In this incident, the criminals claimed to have more than a terabyte of stolen data, including emails, financial records and even scanned copies of passports. This data trove was published online when the company failed to pay the ransom.

Australian hospitals are under constant cyber attack. The consequences could be deadly Screenshot of Cl0p Leaks website showing Software AG financial data available for public download (taken from dark web site).

This is an example of an increasingly common tactic referred to as “double extortion”, in which not only is data stolen and held to ransom, but there is the added threat the data will be posted in public or auctioned to interested parties. The threat of public exposure of the breach, coupled with the potential release of confidential data, can often encourage organisations to pay the ransom.

Potential consequences

A recent ACSC report on ransomware in Australia identified the health-care sector as the most targeted, by a significant margin. This is perhaps not surprising, given the sector’s lack of training, lax security practices and chronic underinvestment in technology and digital infrastructure.

Australian hospitals are under constant cyber attack. The consequences could be deadly ACSC report on impacted sectors for reported ransomware incidents - October 2020. ACSC

Health-care providers face two significant consequences of cyber compromise. First, personal or sensitive data are valuable to criminals. Having such data leaked online is embarrassing and has significant legal implications for the organisation and the government.

A second, more serious, consequence can be seen when a ransomware attack impacts critical systems. The most notable example in recent years was the Wannacry attack in 2017 that targeted the UK National Health Service, among others.

Ransomware attack on UK hospitals.

The NHS suffered a major outage over several days following the Wannacry ransomware attack, resulting in thousands of operations and appointments being cancelled. Wannacry was estimated to have cost billions of dollars globally, with the UK NHS spending close to US$100 million to recover and strengthen its cyber defences.

Australian hospitals are under constant cyber attack. The consequences could be deadly Screenshot of Wannacry ransom demand. Wikimedia

A ransomware incident earlier this year in Germany had deadly results. When ransomware crippled a hospital in Dusseldorf, an emergency patient was sent to another facility instead. She died, and her death has been attributed to the delay in treatment.

Australia has had similar incidents in the past. Last year saw seven hospitals affected by a ransomware attack.

Read more: Defending hospitals against life-threatening cyberattacks

Should we be worried?

Cyber attacks are a constant threat, and most organisations are well aware of the risks to their business operations, intellectual property, sensitive data and reputation.

But in the health-care sector the stakes are higher. Losing data can cost lives, and patient records being stolen is a breach of privacy that can have long-lasting effects for the patient.

With systems intertwined and dependent on each other, just one compromised target can have major implications.

Interestingly, the Cl0p Leaks website (only available on the dark web through the TOR web browser) features the following reassuring statement in relation to hospitals - perhaps showing an ethical streak to the criminal group.

Australian hospitals are under constant cyber attack. The consequences could be deadly Cl0p Leaks screenshot (taken from Dark Web site)

Cyber criminals are usually motivated by profit. Ransomware attacks work because individuals within organisations make mistakes. When combined, there is a strong motivation for criminals to continue these actions and for organisations (and us) to continue to pay to clean up the mess that’s left behind.

Authors: Paul Haskell-Dowland, Associate Dean (Computing and Security), Edith Cowan University

Read more https://theconversation.com/australian-hospitals-are-under-constant-cyber-attack-the-consequences-could-be-deadly-150164

Business News

Inside the Icon: The BridgeMuseum Officially Opens at the Sydney Harbour Bridge

A bold new way to experience one of Australia’s most recognisable landmarks has arrived, with BridgeClimb Sydney officially opening the all-new BridgeMuseum.  Located inside the Sydney Harbour Brid...

Daily Bulletin - avatar Daily Bulletin

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

Portable Toilet Hygiene Standards Explained: Clean vs Sanitised vs Disinfected

In portable toilet servicing, the words clean, sanitised, and disinfected often get used as if they mean the same thing. They don’t. And that difference matters because a unit can look tidy and still ...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

Gold Migration Lawyers in Liquidation: How the Closure Affects Your ART Appeal

If your appeal was with Gold Migration Lawyers, a recent change to how the Tribunal decides cases ...

The pressure cooker: life in urban Australia in 2026

Australian cities have always been demanding. Long commutes, rising housing costs, busy schedules a...

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...