London Drugs closes stores until further notice due to cyberattack
cbc.ca
cbc.ca
I am thinking:
- Manual record keeping (ie, physical ledger)
- Procedures to call insurance companies and verify coverage
- Procedures to ask local doctors to phone in (or hand write) prescription requests instead of using e-prescription system
- Credit and debit card information captured at point of sale with offline device. Processed outside of impacted systems or when systems recover
The post above you is talking about having manual communication with the provincial and federal medical insurance (Canada has national insurance) to confirm customers have the appropriate insurance ready so they can dispense pills, medication, and medical equipment, which is life critical equipment and supplies for many of their customers, without access to computers (which is doable if they had the procedures ready)
It’s to do with business continuity of the pharmacy’s work, nothing to do with breach.
It might be different for Canada though, so this continuity step could be omitted.
All of this is possible, it takes a lot more time. That's why they are moved to "emergency only" business.
Do stores really need to be connected to the internet all the time?
It's not just payments.
No, because giving money is only a part of the transaction.
> Do stores really need to be connected to the internet all the time?
Yes, they need to record transactions (in some cases live for tax purposes), update inventory, and in the case of a pharmacy also check medical files (if such a feature exists in the country in question), verify insurance information, check usage details on the specific drug, etc etc.
Some of those could be batched offline and verified when the connection is back up, but others can't.
> Some of those could be batched offline and verified when the connection is back up, but others can't.
That feels like someone decided that implementing a resilient business continuity plan wasn't worth it (which it may as well be, the impact is great but the likelihood low), e.g. manually making phone calls to verify the needed information, having backup paper copies of documents and so on.
There were more forgeries with paper prescription than there is with online system.
I've had cases where the pharmacy (indeed London Drugs) phoned the doctor to ask them to fax a renewal.
When you visit pharmacy they ask for id and enter your id number system shows them all your active prescriptions and past ones as well, which sometimes helps when your prescription is not renewed for some reason they can give you a week supply while you sort it out.
Basically what would happen was that someone would write it down on a paper form, mail that form off to the typing pool at the corporate headquarter where some clerk would then type it into the central system with a delay of 5-10 days from point of sale to recording into the inventory management system being totally normal, leading to a lot of overstocking and waste.
So to run offline would mean getting a hold of a lot of people that aren't there anymore in addition to reintroducing all of the risk(and fraud opportunities) that running without real time access to centralized data.
When you wake up one morning and you're under a cyber attack and no longer have network access, how easy do you think it is to just start manually phoning in prescription information?
This may come as a shock to you, but the internet has greatly increased the efficiency of business over passing paper around and making phone calls. You can't just flick a switch and go back to the old system.
One of the things that can be batched offline of course is card payments, which sort of negates the OP's point.
https://www.businessexpert.co.uk/payment-processing/offline-...
Some of them do.
A few weeks ago, I was at a Roam Burger outlet in San Francisco whose Toast point of sale system was down due to some server-side problem. They couldn't sell me a burger. Not even for cash. I had a nice chat with the store manager, who didn't have anything else to do. Then I left and ate elsewhere.
Toast docs: "If the restaurant cannot communicate with the Toast cloud, the devices cannot communicate with each other."[1] They have a lot of outages, according to third party monitoring.[2] Their own status page doesn't show those outages.[3] But their outage history does.[4] They're "transitioning" to a system where one of the local devices can be a host for the others when not connected to the "cloud".
[1] https://doc.toasttab.com/doc/platformguide/platformOfflineMo...
[2] https://isdown.app/integrations/toast
Second problem is ill-designed systems which don't take exceptions in to account. Sometimes because of the preceding reason, sometimes just "oops, we didn't think of that".
Let's say you're running a 10000 store burger shop. There is an outage and all of them are offline now.
There's the sheer hassle of recording everything and everything needs to be recorded correctly for compliance. Not only does it need to be recorded, but now it needs to be manually inputted back in correctly as well.
Let's say you could do that. More & more stores are getting rid of their fronting staff for the Kiosk systems. The store won't even have the capacity to keep up.
Now you've got boatloads of cash sitting in these stores that far exceed what normally would be there. Target for robbery.
If you pencil all the orders how will the fulfillment systems know when to ship you replacements and of what? Now reconciliation needs to happen across all of them to make sure they're properly stocked.
That happened to McDonalds on March 23, 2024.[1] Outlets in UK, Australia, Japan, Thailand were down for hours. Burger sales stopped at most locations.
No backup plan. Unlike Waffle House.[2]
This is a serious issue for disaster preparedness. The Waffle House CEO tries to get other key businesses to prep more. He says that if you can keep the Waffle House, the Walgreens, and the WalMart open after a disaster, the community comes back fast.
[1] https://www.bbc.com/news/business-68573106
[2] https://www.hrdive.com/news/waffle-house-serves-up-emergency...
I'm pretty sure there was a time all these were handled without internet connection. it's just as society we decided that resilient fallback methods are undesirabled because of [insert of favourite regulatory rule]
So, no, loss of connection or system break down won't necessarily mean that the trade stops. People have many ways of issuing IOUs and they can go creative.
Pharmacy IT infrastructure is a little more involved than the POS system at the checkout.
> The chain says pharmacists would still support customers with urgent pharmacy needs [...]
Er... which one is it now? If they support customers with urgent pharmacy needs, the stores can't be completely shuttered?
Also, there is no information about any of this (including which stores are open and under what conditions) on their website - but maybe they also no longer control that website?
Customers can still go to another pharmacy.
The rest of the company network though (other servers, endpoints) could well be screwed as well as anything trying to hook to it.
If all stores are incapable to service and apparently no customer data has been compromised, it could be ransomware.
Attacks on Western digital infrastructure will continue until the "technologically talented" in countries like Russia and China (among other places) start seeing it as a way to invite imminent danger into their lives.
You go to your pharmacy and they'll give it to you and make a note for repayment. Or you go to one of the other 500 pharmacies in the Province.
IOW, we have to weigh the advantages vs. the disadvantages. Its not enough to say "Computers make big things easier". Besides, there is probably a reason why antitrust laws exist. Getting too big apparently has more disadvantages then just monopolies.
Perhaps you could link to some?
No it's not. Things like fire safety systems, security systems etc all need electricity.
And you can pay with your watch on a battery powered offline device anyway.
The need is for everything else in the hyper-efficent supplychain.
And our government is worried about online harms haha
https://nationalpost.com/news/canadas-cybersecurity-under-si...
And our government is worried about calling people names