Article Details
Scrape Timestamp (UTC): 2024-12-05 12:28:53.022
Source: https://www.theregister.com/2024/12/05/hospital_cyberattack/
Original Article Text
Click to Toggle View
British hospitals hit by cyberattacks still battling to get systems back online. Children's hospital and cardiac unit say criminals broke in via shared 'digital gateway service'. Both National Health Service trusts that oversee the various hospitals hit by separate cyberattacks last week have confirmed they're still in the process of restoring systems. NHS Wirral University Teaching Hospital, which also looks after the nearby Clatterbridge and Arrowe Park hospitals, downgraded its "major incident" to a "business continuity incident" but is still working to bring hospital systems back online. A spokesperson said in the trust's first statement in nearly a week: "Some services will continue to be affected this week as systems are restored. Anyone with an outpatient appointment is advised to come to their appointment. "Emergency treatment is being prioritized but there are still likely to be longer than usual waiting times in our Emergency Department and assessment areas." NHS Wirral said it reverted to pen and paper operations following the attack last week, but the intrusion hasn't yet been claimed by a known crime group. 'Digital gateway service' was the point of intrusion The same can't be said for the attacks on Liverpool hospitals. INC Ransom took credit for these, which have attracted an overwhelmingly angry reception from onlookers, for the most part due to the impact on Alder Hey Children's Hospital. Per an updated statement, a spokesperson for Alder Hey Children's Hospital NHS Trust, which also oversees Liverpool Heart and Chest Hospital and Royal Liverpool University Hospital, confirmed the source of the intrusion as an unspecified digital gateway service. "Criminals gained unlawful access to data through a digital gateway service shared by Alder Hey and Liverpool Heart and Chest Hospital. This has resulted in the attacker unlawfully getting access to systems containing data from Alder Hey Children's NHS Foundation Trust, Liverpool Heart and Chest Hospital, and a small amount of data from Royal Liverpool University Hospital. "We have launched an investigation which is still ongoing to determine the full facts around what data has been obtained unlawfully." Data allegedly taken from the trust's servers was posted online last week, including what appeared to be the personal details of donors to one of the UK's foremost children's hospitals and its patients. "The attacker has claimed to have extracted data from impacted systems," the statement added. "Screenshots of data the attacker claims to have taken were published online last Thursday. We are continuing to take this issue very seriously while investigations continue into whether the attacker has obtained confidential data. "The investigation into the data may take some time, and there is a possibility that the attacker may publish the data before our investigation is concluded." Additional updates about the allegedly stolen data will be provided as soon as the trust is able to, it said, in line with the rules imposed by the Information Commissioner's Office. Alder Hey said it has made progress to secure the systems that INC Ransom's crooks targeted and ensuring their access continues to be blocked, although this work is ongoing with the help of the National Crime Agency. The process of reconnecting the targeted systems is still to be completed, but unlike the trust's counterparts over the Mersey in Wirral, all hospital services remain unaffected and patients are advised to continue attending appointments as scheduled. Despite calls made from essentially all corners of the infosec industry to stand down the attack, INC Ransom is yet to remove Alder Hey from its data leak site. The NHS and the UK in general have a longstanding policy to not pay ransom demands. There hasn't been a reported ransom payment from any NHS organization since the WannaCry incident of 2017, so it's unlikely that INC, or whoever was behind the attacks in Wirral, will receive whatever they're asking for. And INC should know this already since their affiliates were behind the hit on NHS Dumfries and Galloway earlier this year – another incident for which they weren't paid.
Daily Brief Summary
National Health Service (NHS) Trusts are working on recovery after recent cyberattacks hit multiple hospitals, affecting crucial services and causing delays.
NHS Wirral reintroduced manual operations post-attack, downgrading the incident status but still experiencing service disruptions.
Alder Hey Children's Hospital and Liverpool Heart and Chest Hospital suffered breaches through a shared digital gateway, leading to unlawful data access.
INC Ransom claimed responsibility for the attacks on Liverpool hospitals, and stolen data was posted online, exacerbating the situation.
Investigation ongoing to determine the extent of the data breach, with critical patient and donor information potentially compromised.
Despite restoration efforts, there is a continued risk of the stolen data being published before full security measures can be implemented.
National Crime Agency is assisting in security operations, but the NHS's no-ransom policy remains, as evidenced by past precedents set with other attacks.
All hospital services at Alder Hey continued unaffected, but the broader impact and public outrage have put additional pressure on the security response.