UHS hospitals hit by reported country-wide Ryuk ransomware attack
bleepingcomputer.com
bleepingcomputer.com
> We are down in Florida. It’s a hot mess in the ER today. EMS diversion on cardiac patients because the cath lab is down.
> I work at an inpatient psych site in Philly PA. The nurses told me they asked the patients what they take for morning meds and then didn’t even distribute evening meds bc they have no record of their medications.
> We have no access to anything computer based including old labs, ekg's, or radiology studies. We have no access to our PACS radiology system. No patients died tonight in our ED but I can surely see how this could happen in large centers due to delay in patient care.
https://www.reddit.com/r/hacking/comments/j17aj1/cyberattack...
In my opinion it is the best and perhaps only defense against ransomware. Some trojans stay hidden for weeks, but most go to work immediately. The important thing is not to pay the ransom. The industry would die off like it should. It would be interesting how they could distribute the malware between hospitals, there must be some channel to facilitate that from the network off affected hospitals. Unlikely they hit all hospitals at once. Maybe common credentials. If so, it would need to be checked.
The data is probably extracted at that point, but a way to restore the network would allow hospitals to get back in operation almost immediately.
Backup solutions are on the expensive side. My company had multiple ransomware attacks but we could restore the data nearly on the fly because the backup solution did snapshots over the whole infrastructure.