Hackers threaten to leak plastic surgery pictures
bbc.co.uk
bbc.co.uk
We need a lobbying group that will strong-arm lawmakers into crafting regulation so that our personal information will be treated with at least as much care as ephemeral credit card numbers.
So, seems like you're ultimately advocating for all data to be handled by credit card companies, or similarly hardened targets. In the end this may not gain much; a company with compromised api access is still a good target. Which helps demonstrate another difference: Companies need ongoing access to their data, where payments are 'fire and forget' and thus are easier to protect.
So stating that such data was not leaked is meant to prevent that additional PCI response step.
There are some regulations regarding medical data (Eg, HIPAA) but security seems like an afterthought in most hospitals at best.
The Hospital Group is in a quite bad position: 1) the blackmail, in no definition that's ransom. 2) The data leak has to be reported and potentially they will get fined by the state.
As for taking regulation seriously, I guess it does depend on the industry. Where I work GDPR and regulatory breaches are treated more seriously than downtime.
edit: missing word
On the parent comment I am not saying that hospitals aren't HIPPA compliant but rather that the security expectations of credit card data are higher than medical data.
Obviously that's a horrible strategy and it delivers the expected results..
Yes, as the other commenter mentioned, hospitals do "take it seriously" in the sense that they put a lot of importance on passing HIPAA audits... but passing a HIPAA security audit is a checkbox exercise for security controls that are a decade+ outdated. It means absolutely nothing about an organization's actual security maturity.
They do it for just about any ISO cert, not just ISO 27001.
It is a bit of a dirty secret with companies who work in heavily regulated industries. The companies in question will go through the motions, but make no mistake, you pay for the cert.
Sorry for being vague, just not looking to publicly out anyone. If you Google around, I’m sure you can find more about what I am talking about/much of the controversy around many of the ISO governing bodies.
Welcome to my live :) We 'hired' these experts since they came up with the lowest price offer for our certification. I have been through many certifications in the past, this was one was the most... shameful.
Pathetic grasp of English, IT in general and security controls specifically. We passed that in absolutely zero time, if you exclude the time spend having lunch and 'discussions' about the interpretation of the requirements.
This was PCI BTW.
Next was the local healthcare certification, done by an international auditing firm. Possibly even worst. Total paper tiger exercise. Total lack of understanding of current security standards. Nice ties & suits though and even better lunches to discuss (you guessed it) the interpretation of the requirements.
I get why these guys get the jobs: they know the right people and look the part. But boy, would it not be nice if experts could do these jobs.
If an organisation has the money to spend on doing ISO or something else, it should put the money towards someone who actually has some good skills and knowledge in security and can advise them.
An organisation that recognises the business value in being secure (less risk of fines, reputational damage, more ability to win work with lucrative large organizations) is already in a good place as they've crossed the first hurdle!
The issue with certificates like ISO (and indeed any other kind of kitemark for security) in my view is that it presents the opinion of one (probably inexperienced and cheap) junior person as to whether what you presented them with on the day sounded to comply with a rule. No focus on whether the mitigation is effective. No focus on whether it's relevant or appropriate. No focus on whether it's adequate, or how it sits in relation to the capabilities of a motivated adversary.
A decent understanding of your threat model, your exposure, and how you plan to invest to improve would be far more valuable. Second to this is to then avoid buying snake-oil vendor security products that aren't effective - many of the big organisations breached through solarwinds offer incredibly expensive "AI"-based cyber tools as those are in vogue. Yet all were compromised by a silly supply chain breach from some proprietary DLL a third party vendor was shipping into organisations, which was blindly trusted.
Getting a basic understanding of the old fashioned principles of security and having someone help you take technical measures will be a load more effective than producing paperwork to keep a junior auditor happy.
These certifications are all about shifting blame and minimizing liability. They come up with these stupid standards that do nothing, certify their own compliance and then when they get owned they say "don't look at us we followed established best practice".
They don't actually care about actual security. To anyone who actually cares, the right way to do things will be painfully obvious. Instead we get people who scrutinize the standards in order to find the easiest, cheapest way to fulfill the requirements. Backup? Just copy the MySQL directory! Hashes? MD5 will do. Why encrypt data at all if it's only being transmitted on a local network? And so on...
There are legitimate concerns about the usability of secure medical software but I don't think that excuses some of the absurdities I've seen...
Unfortunately with ISO 27001, NIST 800-171, etc., is that people see having written down policies as evidence of implementation of proper controls. If you have a policy that says you use role based access control, you have to actually do it. If you ha be a procedure that says you backup sensitive data to X alternate location and perform failover tests annually, you have to actually do it.
It’s sad, but 85% of compliance assessors I have worked with essentially look for “do you have a policy? Does that policy say the things the standard says it should? You’re compliant!”.
I blame the companies in part, but I also blame the people who are trusted to objectively and competently evaluate the system’s level of compliance. The standards and assessing compliance to them is great in theory, but in practice, people are...people.
The few areas I will say have succeeded are NIST 800-53/FISMA and FedRAMP. They are not perfect (see: SolarWinds), but the bar for obtaining an ATO and/or FedRAMP accreditation is relatively high.
How do we solve these issues without upskilling a bunch of people who don’t know/care about security? Is there even a solution, or are we just bound to hit some mr robot-esk post apocalyptic scenario before people get their shit together?
In industries where it is a necessity (e.g., government, payment processors, healthcare organizations, etc.), I think there are several things that could encourage adoption.
However, fear of distant future possible outcomes is probably one of the weakest human motivators.
If I could advocate for an approach, it would be through tax incentives, government underwritten insurance that requires adherence and practice of security controls, etc.
My thought is, we can very likely encourage Cybersecurity practices using the same tools we use to say, stimulate the economy (e.g., providing liquidity to housing markets, tax rebates for first time homebuyers, etc.) or adoption of lower emission energy technologies (e.g., tax rebates on purchases of electric vehicles).
Unfortunately, people and government have not seemed to want to make the investment necessary to implement methods I’ve suggested above. Which is bizarre, because some of what we have lost and continue to lose is priceless (e.g., OPM government employee records, IP related to military technologies, etc.).
This (public) medical company went out of business roughly a year after.
https://www.forbes.com/sites/billhardekopf/2020/11/13/this-w...
> security researchers from Website Planet found that Cloud Hospitality stored information from more than 10 million travelers on an unsecured database with no password protection.
That will be taken by credit card companies as gross negligence and breach of contract (they include PCI DSS compliance on all contracts and a requirement that they do the same for anyone that processes credit card data for them) plus anyone going the legal route (and indeed there are reports of a class action that mention PCI DSS compliance explicitly)
My original comment was more in regards the care and security that is expected.
- they have a more regular feedback mechanism (if someone's db gets leaked, they get more fraudulent charges from that company's customers, so they can figure out whose security was bad, and this happens often)
- they have a more credible enforcement mechanism: they can and will turn off your ability to process CC transactions, while a federal regulator in many cases faces a lot of political pushback if they try to actually shut down a medical facility
- the intended (and actual) purpose of PCI was to reduce the number of operators actually storing CC data; if a federal regulator tried to make things onerous enough to force most medical facilities to not store medical data, there would be enormous pushback and they would be forced by Congress to back down
Clearly having straightforward gateways to handle payments can help retailers and raise the bar, but I never cease to be amazed at how many sites run third party scripts on pages processing sensitive information! Bonus marks for using third parties that let other third parties place code on the page!
I think we have 2 orthogonal aspects here - the presence or absence of a straightforward commodity solution, versus the presence of clear security guidelines. The former seems to be what drives better practices, whereas the latter is more guidance people ignore, due to lack of personnel and skills.
>There are some regulations regarding medical data (Eg, HIPAA) but security seems like an afterthought in most hospitals at best.
I worked as a developer for healthcare/hospital websites and the company I worked for took it far more seriously than the hospitals did. We had to babysit them constantly on potential violations and actual violations. The average hospital has at least a dozen different HIPAA violations each and every day because in the end convenience almost always trumps security when a person is stressed and busy. And those were just the violations I was privy to as their web developer - undoubtingly there were even more that I couldn't have been aware of.
When we dropped support for IE8-10 it was a major issue at nearly every hospital we worked with and we couldn't convince them to finally upgrade until lawsuits started happening.
https://www.hipaajournal.com/upgrade-internet-explorer-to-re...
HIPAA compliance is a checkbox and actual security doesn't mean anything because actual security is too inconvenient.
For the famous people, it's a 'nice' extortion, for some 'glossy magazine babe' who claims she is all natural, to come up with evidence of implants, etc. would be devastating to her number of followers, and thus sponsors/payments.
That said, let's hope we're beyond the point of anyone caring about pictures of the human body or whether someone's had plastic surgery.
If I were threatened with something like this, which could be pretty embarrassing since I lost so much weight and have loose skin, I'd tell the hackers that I'll release even more if they leak mine and then attempt to find dirt on them.
Even if they want to use them for ML, this shouldn't be reason to reduce the perceived sensitivity of the data to let them sit on an online device, as the harm hasn't reduced. Hopefully we'll see more threat models based on the impact of harm, not on the convenience to business.
Anyone using Cisco could be breached by someone logging in with the default passwords Cisco keeps adding (and removing when discovered).
These are basic stuff, a newbie IT should know these things.
I will also assume that (large) organizations test the updates, and have an action plan in place (i.e. apply fix/patch/update XYZ, study what it does, read the documentation, make the future-state-config, deploy that config, validate the config). I know, simple words, we 'all' (in the profession) know this but when you need to patch x1000, and the boss is barking.......
Therefore auditors will look and find nothing, but the accounts are buried there within the system if you know about them (i.e. by exploring a firmware dump and finding the password hash and reversing it).
If these are documented (e.g. IBM has these notorious RedBooks of 500-700-1000 pages) then one should spend the time to study before implementing, securing, auditing, and-other-verbs.
Again, the only 'excuse' I can accept (not really) is that "management" knows that the staff is not enough and they cut corners.. in which case you crucify the COO in your report, not the poor admin(s).
Being caught in a lie about your main product being fake is a win for the public in my book.
I remember shopping at a well known, large electronics store in NY. The cashier insisted on taking down my phone number and email. When I asked why, he said "if you decide to return the items". I told him I will produce the receipt, but this turned into an argument. I didn't want to waste other people's time over a 30$ purchase, so I just left without buying. This is just a small example of the abuse that we put up with everyday
What kind of pointless statement is this? What is "many"? And does that imply that "many," "most," or "only a few" pictures will include the patients' faces?
I guess pictures of nose adjustment patients most certainly include faces, and pictures of nipple corrections probably don't.
(which isn't to say that they'd purposefully choose two different implementations. Rather, just that if i'm using poor person doctors i'm unsure they'd rise to the new "standard" of security practices)
But they simply don't care.
In the past before computers they would be putting these in files on a large file folder shelving units with colored folder tabs behind a counter and the only real security was a receptionist that would stop you if you tried to interact with it, and they locked the door to the office when they left. If someone broke into the office back then too, your medical records would've been stolen & unencrypted (beyond the illegibility of most doctor's handwriting) and as a society, we were ok with that security level.
Harsh fines are probably the best way to make doctors care though. If they know they risk financial ruin for not securing their records, they'll have a strong personal incentive to remediate their ignorance.
For all you know, they could have had that system too, the article does not say what it was.
BD-R (except LTH) use an inorganic layer to record on.
Now they should be doing 3-2-1 backups. With S3 they'd be paying $160/month (for storage, not counting other costs) for 8TB or $40/month for BackBlaze B2. That's 8,000 customers.
They're in England so some variance in pricing. But it would be relatively inexpensive to buy big drives, sync them to a set in the office, and back them up online. Where the doctors or whoever is running the clinics can SEE the data is still there whenever they want.
I agree that there should be increasing worry about keeping information that you don't need, whether it's intimate pictures of your surgical clients or people who bought from you 5 years ago and not since. But it seems like keeping things handy will be an impulse that's hard to overcome.
I did some IT work for a plastic surgery practice in the US many years ago. I was adding some storage to an existing server. I was shocked to see that the practice was keeping all their before / after photos online going back years. Not encrypted. Hanging out in Windows file shares with lax permissions.
It certainly gave me pause.
Maybe some software providers in this space will think about handling this better.
In contast, anything more secure tends to add inherent friction (since just blindly giving access due to some potentially replayed hash of a user's likely weak password isn't exactly going to be appropriate in a secure setup). And if it adds complexity, people still go for the old solution.
I hope they had backups - I've often caught out the same Windows SMB-using orgs out when checking their backups and discovering both of their weekly-cycled drives are empty and devoid of backups, despite having been diligently swapped out according to the schedule!
A plastic surgeon might want to look at before-and-after for a few of their "branches" (specific plastic surgeries or repeated applications of a technique). "When I did celebrity-A I notice they sag too much in location-X, whereas for celebrity-B where I changed the procedure location-X looks much better." "Celebrity-P has the same odd nose Celebrity-K had ... let me consult my notes and the before/after for Celebrity-K."
(Although I'd hope they obscure identifying details and get permission from the original patients...)
The only place I can't get away with it is a dentist. They love giving x-rays...because apparently that helps with scaling.
They normally ask in the millions. Generally anyone can pay for it. You could buy it instead if you want. (There is an Auction section, but it's not open for TheHospitalGroup atm)
The amounts they ask from even small websites I find way too high. Perhaps their website asks high so when they go lower they get paid.
If you don't pay and no one else wants to pay, it goes public.
REvil .onion - "At the beginning of next week we will post the first batch of files, namely: Pacient Personal - 20гб TMG OFFICIAL Documents - 50гб"
> why was this even a target?
I assume like almost all hacks, even at the nation level, it's opportunity more than targeted. This website had a sploit, then they found real data behind it.
When you’re earning (tens of) millions by extorting companies you aren’t going to be very interested in selling their data for tens or hundreds of thousands.
So a lucrative target might be someone who traveled from outside the US to have work done to hide it, especially if they were relatively young.
They probably don't care for the photos. They care about making money and want to keep making money in the future.
Reminds me of a statement put out by White Star Lines in 1912:
"None of our passengers payment card details have been compromised but at this stage, we understand that some of our passengers personal lives may have been affected."
This isn't a ransomware attack, they're not encrypting the company's drives and demanding a ransom to unencrypt them. Not every "I hacked you now pay me or bad things happen" situation is ransomware.
This is "the malware got in and sent copies back home; now home base is threatening release and expecting payment to prevent it." To me, this is blackmail done via hacking, not ransomware.
> Ransomware is a type of malware from cryptovirology that threatens to publish the victim's data or perpetually block access to it unless a ransom is paid.
(added emphasis)
Here's the third sentence from that very same paragraph:
>It encrypts the victim's files, making them inaccessible, and demands a ransom payment to decrypt them.
Not everything can be explained in a single sentence.
They copied the data, and they want money otherwise they will release it. It's ordinary blackmail.
No, a ransom is a fee paid for the release of something you value. Cryptography is one way to take a user's data, and release it back to them on payment.
This is blackmail. They want payment to not release something.
Calling this "randomware" subtly blurs the line between copying and stealing. The attackers here didn't remove access to the data (clearly stealing), they made a copy (clearly a crime other than stealing, at least in my view).
It's more like blackmail than kidnapping.
> Ransomware is a type of malware from cryptovirology that threatens to publish the victim's data or perpetually block access to it unless a ransom is paid.
What makes "stealing" particularly bad is that the rightful owner no longer has possession of their property. That's not necessarily the case with data.
In digital, information wants to be free and many kinds of resources are effectively unlimited. There is no material scarcity. Therefore, theft, in the digital world, can't be the same as it is in our analog world.
To be fair, this also applies to copyright and peoples' foolish notion that they can protect data without a great amount of preventing otherwise normal "physiological" processes. (Ironically, rather than having a wake-up moment where people realize their folly, we've institutionalized these resource-scarcity regimes into resource-abundant versions in the digital world)
To summarize, info wants to be free, and since theft requires extra effort to deprive someone of what you stole, does that definition of theft really apply here? Or does it need to change given the context? And, as a secondary point, people like to think they can protect data but their brains are stuck in our analog, resource-scarce world
There is nothing being returned here, since the hospital has not lost access to the data, and the threat is that private data will be published.
This is just blackmail.
What is it then, if you don't have the legal right to the data?
It's not like we need the law to explicitly allow types of access. Anything not explicitly disallowed is allowed without a special name.
"Stealing" happens when the original owner is deprived of the thing.
Seriously. Theft requires the property owner be denied their property.
What happened is someone made a copy they were not supposed to.
Textbook infringement.
Both "hacking" and stealing are illegal in most countries, but they're still completely different actions: one is taking a physical object from someone, the other is sending and receiving electrical pulses trough a wire.
You wouldn't call stealing and killing by the same word, either, even though both are illegal.
I think in a way, ransomware authors are following the "free market" approach, trying to best monetise their unauthorised access to other people's IT systems. Perhaps the prevalence of ransomware will eventually help businesses to properly cost in the risk of security to their business, and get their security in order, as there's a tangible cost threat?
Adding: Wikipedia is also not necessarily authoritative.
What moral question?
This thread is someone questioning calling it was a ransomware attack, it was one. Being a ransomeware attack doesn't preclude it from being blackmail, and I don't think anyone you replied to has questioned the morality of it...
If you heard tomorrow that there were a bunch of plastic surgery before and after photos online, would you even go look? What is the threat here - that people will search the data for people they know and...make fun of them? Really?
It doesn't seem like that was done at these clinics.