Hackers disrupt payroll for thousands of employers, including hospitals
npr.org
npr.org
Hospitals are why I don't "blame" underinvestment into cybersecurity. Their #1 goal is saving people's lives, not messing with IT issues. You want hospitals to be paying for important equipment, important people, important skills. The whole IT part is just supporting the administrative tasks.
But yes, it means that paying the ransom is the better move a lot of the time than to actually try to restore IT services.
--------
At some point, it becomes more efficient to go after the hackers, rather than trying to defend every single Hospital.
Ex: When REvil accidentally hacked an oil-pipeline (instead of a more passive target), the blowback was so severe that REvil disbanded and ran away. It caused an international incident, to the point where Russia has caught the attackers and is offering them up to the USA as a peace offering.
What is rather unfortunate, is that we put more importance to our oil-infrastructure than our hospital infrastructure. But these ransomware attacks on health care has been going on for years. Its not new.
Technically, profit tends to be the #1 goal, at least in the US. Consequentially, this also drives a lack of investment in cybersecurity. Also, US hospitals have some of the most opaque pricing and billing processes of any industry that I can think of, which makes it much easier for them to recoup losses from patients that can't pay by shifting those costs onto the insurance provider and other patients who can pay. This is one of the reasons why basic things like bandages cost so much in an ER. Despite efforts to bring transparency to medical billing, hospitals are still resisting the push to publish pricing and explain their business models in more detail. We've become so culturally desensitized to the state of US healthcare that we're now just defending it as "we really can't expect hospitals to do any better than they are right now", and that kind of apathy really scares me.
As the healthcare sector continues to be consumed by private equity, I don't expect to see the situation to improve. Again, it's all about profit, saving lives is secondary.
UK's hospitals fare no better in terms of cybersecurity. This is about the culture of nursing / doctors / hospital administrators, which is largely shared between USA and UK.
This isn't a systemic issue that is solved by nationalizing health care like UK did.
USA health care system, culturally, is about saving lives. Whether our system matches it is another story. But the underlying people largely do the right thing.
------
I think the systemic issues regarding health care / infrastructure / investments are wholly independent of this cybersecurity issue.
With all respect, but for someone who had lived in the US after moving from EU, I'd say it's first and foremost about making money. It saves lives where saving is needed, but I'd argue vast majority of cases are outpatient and the culture is strikingly blunt about milking the patient.
The whole market is wildly distorted- starting with doctor education up through private insurance and government programs like Medicare and Medicaid- that simple answers like this totally miss the mark.
The pandemic showed a number of areas in healthcare where people were generally ignorant. For example, thinking that hospitals have tons of reserve capacity to handle extraordinary events. Even well before the current situation, hospitals (community) tended to run at about 80% occupancy. Far from being a profit-consideration, even the department of Health and Human Services mandated that hospitals had to run at least 55% occupancy, or they lost benefits.
But who made such statement in this discussion?
I am not providing my "answer" to the US problem, I am merely noticing how strikingly different approach the healthcare has here, so I reject your insinuation.
To be honest, I don't need to care who's making how much money to make a point – all I know that from my perspective, at the end of the day it is about milking the patient and it differs wildly from the general EU experience.
While profit no doubt impacts the decisions, it doesn't appear to be the primary driver of cybersecurity lapses.
* The organization has one or more squeaky wheel employees that force everybody else to consider security where they wouldn't otherwise.
* The organization or another in the same industry has already had a very painful security breach.
* Security itself is part of the selling point.
Non profits are slightly different, but they still experience many of the same problems because the goal is still getting the most done on the budget you've got.
I will respond to that partially: where profit is not a primary motive, i.e. in countries where healthcare is public, it tends to be centralized on federal or regional level, and, as such, much of the IT and cybersecurity is a lower, shared cost incurred by the government.
Taking my native Poland as an example, there is a single country-wide portal available for patients (http://pacjent.gov.pl), as well as a single, centralized API for doctor/hospital software (https://cez.gov.pl/interoperacyjnosc/interfejsy/) and a bunch of helper systems (https://cez.gov.pl/projekty/nasze-systemy/project/rejestr-as...). Naturally hospitals would have their own 3rd party systems, etc., but the tendency is to unify everything, which logically reduces number of attack vectors.
Hopefully someone with a better experience in the field can attest to that.
At the same time, we should make sure that any insurance company that chooses to pay the criminals instead loses their license to operate.
Since the AMA is an organization of medical professionals, one must conclude that it reflects their position: protectionism for their field.
The point is, just like it says in the Preamble to the U.S. Constitution - "...insure domestic Tranquility, provide for the common defence..." - that protecting everyone from large-scale, organized, high-skill malicious activity is a bedrock function of any national government. NONE of the hospitals, water treatment plants, small corporations, city governments, ordinary citizens, etc. should need to worry about high-cost, high-skill self-protection against ransomware groups - any more than they should have to hire and equip private security forces to protect themselves against mafia enforcers, Russian paratroopers, or missiles launched from North Korea.
Banks and stores in US routinely employ private security. There is no reason why US public should foot the entire security bill of Tiffany's or CVS.
US gov should have defensive and offensive cyber capabilities deployed strategically to assist and deter, but uncle sam can't babysit each and every it vendor or client.
US gov also needs to hammer shit IT practices and make it too expensive for bad guys to do harm and too expensive for "good guys" to be morons.
Para. 4 - Lordy, yes. Though that needs to be competently done. Starting with setting up a computer version of Underwriters Laboratories - that could drive the sellers of Internet of T*rds crap out of business (at least in the U.S.), revoke Experian's right to operate a database full of sensitive financial information, etc.
A few examples;
Ascension Health - $5.7bn net income on $27bn revenue in fiscal 2021 [1]
Cleveland Clinic - $1.3bn net income on $6bn revenue in H1 2021 [2]
Mayo Clinic - $728mn net income on $14bn revenue in 2020 [3]
"Non-profit" doesn't mean they don't like profits just like corporations. It's a designation meaning no shareholders, as in money made by the organization stays within the organization.
1- https://www.fiercehealthcare.com/hospitals/ascension-latest-...
2- https://www.beckershospitalreview.com/finance/cleveland-clin...
3 - https://www.beckershospitalreview.com/finance/cleveland-clin...
Sure, some places have two (or more) hospitals in the region, but often there's only one and the choice is just go or don't go. It is one of those areas, like utilities, where it really is _not_ a free market.
Two years ago (October 2020) when COVID first started and hospitals became cyber-attack targets, all the government agencies put out guidelines for them to follow.
https://www.cisa.gov/uscert/ncas/alerts/aa20-302a
As part of this, the hospital I was a sysadmin at sent me to cyber-security training. I was excited at first, it was part of a big healthcare coalition, running out of the top university in the state...
And we get to the classes. Most of the people there were the CISO, VP of cyber security, etc. Our entire first day was wasted just getting people signed into the labs. Web-based VMware client, a mix of Windows and Linux virtual machines, depending on the excerise.
I realize these people aren't 'hackers'. I realize all of these people don't have VMware or Linux experience. But I felt like I was walking my grandmother through creating an Amazon account. And all of these people are making 6 figures and the head of something security related at the largest hospitals in the state. Insanity.
Hopefully these people have very capable staff under them. The second day, we only wasted half a day with getting people to be able to log into a VM and follow step-by-step commands. It was basic stuff, what you'd find in a 'Hacking for Dummies' book. You'd run Kali Linux and do a vulnerability 'attack', analyze some files, patch some software to it was no longer vulnerable...
When we got to part that was a short C program illustrating a buffer overflow, I realized the wrong people were attending the class. I think most others did as well as you never heard another peep from the 30 people on the Zoom meeting until the very last day, asking how they could get their continued earning credits or units or whatever they are called.
Too many orgs go into do or die mode and try to do everything and do it poorly. Accepting risk is a liability no person in authority ever wants to sign, even if it's accepting the risk of an earth destroying comet. They will ask you to do what you can instead, when you don't have enough resources to even begin implementing the needed controls.
Often in info sec governance literally the only way for us to get leadership to accept a realistic scope is to do as much risk transference as possible.
The current security paradigm includes a lot of rapid adjustment. Upgrade this package immediately, ship a new binary using an upgraded library, firewall this off right now, etc.
I think that might be fundamentally incompatible with an environment where downtime can be counted in human lives. The risk calculations are a lot harder when death is a potential outcome of downtime caused by upgrades.
I don't have a magic bullet solution to that, but I do think that gets lost in a lot of the armchair security discussions around hospitals. They operate under very different expectations than the rest of us.
Have an expressly stated set of goals about the above as well as a core set of stable priority maintained software that gets extra security vetting. Formal analysis, whole classes of students in different locations scrutinizing and learning every line of code, function, and the overall design. Formal validation where possible.
Several attempts at creating such systems have been made in the past, but little effort has been put into actually leveraging them in the wider world.
On a similar vein: Hackers Apologize to Arab Royal Families for Leaking Their Data
https://www.vice.com/en/article/n7nw8m/conti-ransomware-hack...
I appreciate my time working with some great lawyers because I learned so much and still have many useful contacts (do you know the best IP lawyer in your state?) but it really created a quiet seething distrust of lawyers and the legal system in general.
Ive never seen the worst people in society hailed as the paragons of the community as much as lawyers.
The biggest hospital gig I had was for the neurosurgeons and they got stuff done faster than any other hospital department because they had their own building, the pull, and the money to do so and due to stories I heard I just knew they were an outlier.
Our system is setup that we defend the networks we've been assigned to. The greater cultural problems are someone else's problem. We don't actually look outside of our own networks.
Hospitals getting hacked? Well, that's sad, but not our problem. Not until they pay us at least.
------
Granted, I'm not sure what we _should_ be doing about this issue. But at least acknowledging our current culture would be a step forward. Good IT security comes from the top, from a culture of security.
That said, you have to know what you are talking about or admit you don't. Doctors are used to being mislead by the best, and if you try to mislead or bullshit them they will know and you've lost their trust. Admit when you don't have in depth knowledge about what they are asking for and they will respect you for it. In a lot of cases you may be able to learn from them, as there interest is specific when you will have to deal with the entire environment.
The other important thing is don't waste their time. A lot of Doctors are working 18 to 20 hour days, and don't have time for you to be disorganised. If something is going to take a long time to do, then tell them so they can plan around the job. If a quick task suddenly looks like it's going to take longer, let them know as soon as you can so they can plan.
Keep at the top of your mind that the clinical staff you are supporting are their to save the lives of real people, they are not there at your convivence. Remember one day you will be a patient and you don't want your doctor to have to stuff around with a unhelpful IT specialist.
Just conjecture here, but this may be because the healthcare system is more resilient. Even as bad as it is, disruption to the healthcare system in these attacks is more local and more easily addressed by load shifting. Contrast that to oil infrastructure which may have more single points of failure as well as being more interconnected to the economy as a whole.
And yet everything crumbles and collapses when there's an IT outage. How interesting.
These organizations might not be culturally accustomed to have IT at the core of their business/mission, but it very much is. They might not value engineering skills and people in IT, but they have evolved an absolute dependency on those over the years.
The issue here is cultural, not technical. These randsomware attacks, breaches and outages are completely self-imposed. They can end anytime as soon as the hospital wants it. All they have to do is value and acknowledge IT as a fundamental pillar of their organization. Else the cycle will endlessly repeat itself.
You can't "invest" yourself to become secure.
In theory, perhaps, but it's going to cost you through the nose and beyond.
Reasonable security is reall very cheap, but involves saying "no" a lot. That's not something most organizations are very good at, so there's this whole cottage industry thriving on the promise that you don't have to if you buy a lot of expensive products instead.
This comment may seem flippant, but beneath that thin veneer it's completely serious. It's not primarily a question of money. No amount of money can upgrade an infrastructure in place to be secure.
I'm sorry, but this is completely backwards. It implies some global authority over communications, which is complete opposite of the Internet environment of communication in spite of hostile noise. Yeah sure it seems mighty cool that the US can pressure Russia to go after a notable group and shut them down. But thinking that can scale up to eliminating "Internet crime" is hopelessly naive. Unless we want to end up with a globally surveilled permission-required network where every node needs some associated identity, as well as making people even more liable for security failings (when their identity gets used as a proxy to attack others), it's a non-starter.
What needs to happy is that hospitals, every business, and really every individual needs to develop a small sense of network security. This is akin to how everybody has developed a basic intuition about electricity - ie don't touch it unless you know what you're doing or you will get shocked, start a fire, and/or die. The Internet is a multi-actor environment and connecting your stuff to a multi-actor environment is not free. If you want to avoid increasing the cost, knowing what you're doing can be simply consist of avoiding networked devices, getting explicitly security support and indemnification from the manufacturer, etc. The current culture of just plugging whatever in, proclaiming "works for me!", and then promptly forgetting there could be other implications is what's not sustainable.
If you're going to adopt a new tool, you maintain it. They seem to sterilize scalpels just fine, so they should be able to maintain second-order tools, too.
Knowing this country, I’m sad that this choice is likely a foregone conclusion.
That’s a perfectly fine business model for a manufacturing plant, but we have to ask if that for-profit model makes sense for health care. With a public system, you can just decide to pay doctors and nurses more until you actually have enough of them to run the system. You can make cost / service level trade-offs intentionally rather than “how much capital can we extract before the whole thing collapses”?
The amount of friends and peers of mine who gave up a career medicine because the ridiculousness of this whole system turned them off completely is really saddening.
I understand that we should be diligent about making sure the people we entrust our lives to are trained and trustworthy, but do we really need:
- 4 years of undergraduate studies that have ZERO medical treatment curricula
- 2-3 years of work experience if you don't get into medical school right away
- Studying for the MCAT concurrently and trying to get a high score
- 4 years of medical school
- A high stakes test that determines if you will receive the residency you want
- A lottery system that "matches" you with hospitals for residency
- 3-5 years of this residency in hopefully the specialization of your choice (depending on if you passed that test), hopefully in a location you desired. You will be paid very little and work 80+ hour weeks
If you track this entire system perfectly, you will become a full fledged doctor that makes the 6-figure salary at around 32 - 35 years old. And every step of the way is a huge filter that break and washout many promising potential doctors.
And then there is the medical school debt that you will be saddled with even if you washout.
This system is madness and we need something more efficient to both incentivize more people becoming doctors and less people washing out.
> And then there is the medical school debt that you will be saddled with even if you washout.
> This system is madness and we need something more efficient to both incentivize more people becoming doctors and less people washing out.
Who has the control over this? A legalized monopoly here in America (the AMA) that also famously restrict the number of available residency spots. This creates an artificial scarcity and props up the price of care for the public. Same organization that lobbied and got the government to create laws mandating “certificates of need” [0] to make sure they wouldn’t have to compete in a fair market. This can end at any time. But it won’t because this would go against their interests.
Nursed are well paid but arguably should be paid more, they're regularly reaching 6 figure salary.
Side note, a lot of doctors in their late 30s are single for a reason. They literally do not know how to turn work off. Not a bad quality to have in a doctor, but also not a good one to have in a prospective partner.
Pilots have mandatory crew rest. Truck drivers have mandatory rest. Doctors need mandatory rest too. Any job that involves real risk to life should have rest procedures.
* Each duty period must begin with at least 10 hours off-duty.
* Drivers may work no more than 60 hours on-duty over seven consecutive days or 70 hours over eight days....
* Drivers may be on duty for up to 14 hours following 10 hours off duty, but they are limited to 11 hours of driving time.
If we just raise the doctor's salaries to $500,000/year, it won't really solve those other, more important issues.
------
Similarly, if we lower the cost of creating Doctors, I don't think we'll necessarily see a drop in their salary. We're in too much of a doctor shortage for that to happen, at least immediately. (Of course, the market / supply+demand will shift things in the long run, but that's over a 20+ year cycle and not over a short one)
From having been around residents, I can tell there's a lot of work getting done 2-3 times because of poor communication or sleep deprived professionals making mistakes. And there’s absolutely no automation in the field!
Why not simply work smart instead of hard?
Correct. Duplicated work, endless shifts because it's believed that switching doctors is more dangerous than having one work for 24 hours at a time are all accepted practices in modern medicine.
NASA (and the military) figured out how to solve both issues back in the 60’s as it was impossible for manned flight to work (or nuclear subs). The medical field still has not, and there’s no incentives to (it’s not result-based, unlike NASA).
In this world, bosses end up holding power over their underlings. A boss who uses this power capriciously is tyrannical. A leader should use their power to achieve the shared mission of him and his followers, not arbitrarily.
There's a time and a place for ribaldry, and an interview isn't one. Generally those are optional situations that people can avoid if they don't want to hear it. This, and other sorts of 'tests' that some bosses use in interviews to test for 'thick-skinnedness' is equivalent to seeing if an underling will tolerate arbitrary abuses of power. It's equivalent to a test for absolute loyalty and servility, to see if the underling will be a yes man.
If a leader crosses a line for no good reason, perhaps by cracking a too risque joke, he or she should apologize and tone it down. It's about using your power responsibly and respecting your employees as you will have them respect you.
As a current prisoner, I'm not sure this guy had it right. It's usually the guards that supply cellphones and they just bring them in pockets or bags. Or nuns. I had a nun smuggle in a C# book with accompanying CD-ROM.
Drugs often travel in your "prison pocket", but I've never heard of anyone jamming a cellphone up there.
Luckily, before I went to jail, I had been given this book, the knowledge of which proved useful inside:
https://www.amazon.com/How-Hide-Anything-Michael-Connor/dp/0...
There are usually dozens of places to hide things that don't involve your anus.
Reminds me of the Panera executive who got upset (seemed to be confused) when a security researcher wanted to exchange keys…. dude thought it was a scam / sales tactic.
https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s...
https://finance.yahoo.com/quote/KRO/
Their stock looks fine. You'd never know their business is inoperable.
I know customers of theirs that just said 'screw it' and wrote their own payroll/timeclock systems. They don't have a 100% replacement yet (not a small project) but at least they can use cards to clock in and track hours.
I'm surprised every employee who uses the system hasn't had their personal information posted to the dark web yet.
If you were going to steal IP, stealing from Kronos would probably be pretty low on your list, because you're trying to build something that works, right?
UKG is privately held.
The org I work for transitioned their Kronos from onsite to their multi-tenant cloud system. And it's been an absolute nightmare. Both software suites are a mess but transitioning to their cloud suite is like downgrading at least 10 years of upgrades.
I was surprised when it first happened there wasn't more publicity. To find out it is still going on a month later is jaw dropping.
Ransomware attacks on hospitals is a bread-and-butter move by the hackers in these times. I've been hearing stories like this since 2016.
Hospitals pay the ransom and have terrible IT infrastructure. They're the ideal target.
Also I bet these systems have lots of little moving parts under the surface no one really considers, but these little parts prevent an upgrade.
Payroll is highly regionalized problem - every state and city has different rules/taxes and very unique ones as well. Its often not so simple to generically describe a payroll tax and plug in different configs per region. Much hidden complexity that's grown organically over time as laws/taxes change (which they do!).
A rewrite would be an archaeological dig. I would have to be paid a lot to take that problem on.
It's also not trivial software to manage, so often it's outsourced as a service (run by humans) on top of software that cut the checks for your employees. Makes me think that the margins are low? I dunno.
Modern companies like gusto are changing this
I know for our company to do work with DOD we had to meet a bunch of criteria and make changes to our systems to comply. But it wasn't a standardized process at all.
The very name of the company sounds like a scam. Why would you entrust your payroll to people who chose a name like this?
> Unfortunately, our payroll processor, Kronos, has been hit with a ransomware attack, making them temporarily unavailable. We are tracking things manually for now and will issue pay manually, if they are unable to get back online. We are doing everything we can from our side. Sorry for the trouble. Elon
And I'm someone who generally finds Musk hard to like.
> my issues with apologies from CEOs or companies is that they are generally lacking action or avoiding accountability
Think of it this way: If the employee doesn't deliver on a major obligation, there is no apology, I'll do better next time; they are gone.
And it sounds like that's exactly what he plans on doing, should there be extended problems (as much as it pains me to defend him)
We can talk a lot about the morality of paying ransoms, but should Kronos be putting their clients through so much to avoid it? Should they make that decision on their behalf?
The only statistic in the article that gives a clue how many hospitals were affected appears in the statement:
"In Montana, more than 250 nurses at Missoula's Community Medical Center have missed out on pay due to the hospital's decision to pay employees by duplicating an early December paycheck"
So in this particular company, some nurses were forced to accept their expected regular+OT pay and will have to wait a couple more weeks for any extra overtime they might be entitled to.
How many healthcare workers were affected? No more than any other industry. I couldn't find any news on the internet actually revealing how many workers in general were affected other than "up to thousands". So how many might be health care workers? Up to hundreds? So maybe 0.005% of healthcare workers have been inconvienced?
So my question is, why has NPR specifically addressed the impact to "hospitals"? Why is the impact to healthcare workers more important and news-worthy than to the impact to everybody else?
> "The outage is an unneeded administrative nightmare timed precisely as the omicron surge is hitting hospitals, Riggi said."
Ah! The outage was "timed"!!!!
The evil hackers intentionally timed the attack to threaten COVID victims!!!! My god! They're MONSTERS! attacking and murdering the weakest of us! It's outrageous!
What should be done? Is it's time to fire up the gas chambers for these inhuman hacker terrorists? Or maybe it just time to click on NPR's clickbait title?
Actually, in this case, the shoe fits.
The hackers are criminals and extortionists. No more. The impact of the crime is embarrassment to businesses, time and money recovering from data loss, and an inconvenience to workers across all industries.
NPR played up an angle that doesn't exist in any meaningful or significant way. Why? More clicks.
I expect criminals to be assholes.
I expect more from NPR. They used to have more integrity and objectivity than they do today.
I think where we disagree is the impact of the crime. I'm pretty sure the UKG hit is going to do a lot more damage to UKG's customer's customers (patients not getting good care because the hospital couldn't write a paycheck) that "embarrassment" and "data loss".
Try tens of thousands of employees, easily. This outage affects more than just nurses trying to clock in. It's used for fire, police, dispatch, EMS, city utilities, auxiliary staff like the hospital cafeteria workers, and so on.
This is a huge problem for many of us.
Bitcoin is a currency, so no, any holder of any US or NATO allied regime's currency should be equally culpable as the currencies have their value rooted in military-enforced petrochemical trading monopolies. Dollars and francs both.
PS: I'm not even a fan of cryptocurrency.
A beggar does have the same impact on the climate as the CEO of Exxon. Asking someone not to support crypto is not the same as asking them to cease living.
By supporting cryptocurrency infrastructure you are indirectly supporting those illegal transactions. Now you could say the same e.g. for bakers that they also feed war criminals or whatever, however bread’s main use isn’t feeding criminals. It’s much more akin to providing money laundering services.