ESET: The health sector was heavily attacked by cybercriminals

The computer security specialist company studied the growing attacks on health institutions that highlight the need to improve cybersecurity policies

ESET reports that an increasing trend observed year after year, and that 2023 is no exception, are cybercriminal attacks focused globally on the health sector. A report from the World Economic Forum already reported until the middle of this year that the health sector suffered 22 % more attacks compared to the same period of the previous year, making it the third most attacked sector worldwide, behind education and research, and finance, insurance and communications, which occupy first and second place respectively.

“The health sector is one of the most vulnerable and attractive to cybercriminals, who seek to obtain economic benefits or cause harm to the population. The consequences are highly dangerous for society, since they affect everything from ambulance care to the provision of medications and the performance of surgeries. This is one of the strong points that make cybercriminals target these entities: the response to emergency situations cannot be hindered when people’s health is at stake,” explains Camilo Gutiérrez Amaya, Head of the Research Laboratory of ESET Latin America.

Since the pandemic in 2020, ransomware groups have intensified their attacks on hospitals around the world, taking advantage of the fact that systems were working at maximum capacity. Cybercriminals saw this as a plus to pressure the payment of ransoms after attacks.

A report from ENISA (European Network and Information Security Agency) of the European Union reveals that until mid-2023, the most frequent attacks were: ransomware 54 %, data threats 46 %, intrusions 13 %, attacks DDoS 9% and supply chain attacks 7 %.

Resonant cases in 2023 and preventive measures for 2024

The year began with the attack on the Hospital Clínic of Barcelona, ​​attributed to the group RansomHouse, which affected the services of the medical institution that had to coordinate with other hospitals in the city to provide the required care to its patients, especially those at risk of life. .

This same group was also active in Latin America and, in October, affected the health and justice services of several countries, in what is known as a supply chain attack: the attacked company provides digital services to numerous companies in the region and the world, and the group used this link as an entry point.

In August, Ransomware as a Service (RaaS) group Rhysida launched an attack on Holding Prospect Medical in the United States, affecting more than 16 hospitals and 116 clinics across the country, which had to suspend all of their IT systems.

In the same month, this group attacked the Argentine National Institute of Social Services for Retirees and Pensioners (PAMI), directly affecting the care of affiliated people and the digital documentation system. More than 18 GB of information and 1.6 million files were leaked. As with any leak of sensitive data, the consequences may be yet to come, with phishing emails, blackmail and deception of patients of that service.

The Department of Health and Human Services of the United States identified that the main vulnerabilities that can be exploited by malicious agents and compromise the integrity of systems and the confidentiality of data are: web applications, encryption flaws, software and systems unsupported operating systems and known exploited vulnerabilities.

How to protect yourself

“The growth of cyberattacks in the healthcare sector must be addressed by paying attention to its critical vulnerabilities and understanding the overall threat landscape. Investment in computer security and the implementation of comprehensive cybersecurity policies will be fundamental to confront and protect systems that are so vital for society and the well-being of the population,” says Camilo Gutiérrez Amaya, Head of the Research Laboratory at ESET Latin America, a leading company in Proactive threat detection.

With information and image provided by ESET and Comstat Rowland Comunicaciones Estratégicas Integrales

Visit our news channel on Google News and follow us to get accurate, interesting information and stay up to date with everything. You can also see our daily content on Twitter and Instagram

You might also like