Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% -...

32
Ransomware: The Secret is Out, Healthcare is Vulnerable Rod Piechowski, MA Senior Director, HIS, HIMSS

Transcript of Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% -...

Page 1: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Ransomware: The Secret is Out,

Healthcare is Vulnerable

Rod Piechowski, MA

Senior Director, HIS, HIMSS

Page 2: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Speaker has no real or apparent conflicts of interest

Page 3: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Learning Objectives • Identify the types and sources of ransomware • Discuss the challenges presented to healthcare organizations • Review ways to address the risks of ransomware

Page 4: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Why is Healthcare Vulnerable? • Adoption of digital records • Antiquated systems • Ease of exchanging ePHI • Heterogeneous networks • Rapidly evolving threat landscape

Source: KPMG 2015 Cyber Healthcare Survey

Page 5: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Greatest Vulnerabilities • 65% - External attacks • 48% - Sharing data with third parties • 35% - Employee breaches and theft • 35% - Wireless computing • 27% - Inadequate firewalls

Source: KPMG 2015 Cyber Healthcare Survey

Page 6: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Top Information Security Concerns • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% - Medical device security • 31% - Aging hardware

Source: KPMG 2015 Cyber Healthcare Survey

Page 7: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Prepared to Defend

66% Payers

53% Providers

Source: KPMG 2015 Cyber Healthcare Survey

Page 8: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Security a Board-Level Topic?

89% Payers

85% Providers

Source: KPMG 2015 Cyber Healthcare Survey

Page 9: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Attack Frequency • 81% have been attacked in last year

– Others are either secure, or: – Not willing to admit attack, or: – Don’t know they’ve been compromised

Source: KPMG 2015 Cyber Healthcare Survey

Page 10: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Malware Threats • Viruses • Worms • Spyware • Adware • Rootkits • Trojan Horse • Keyloggers • Scareware • Ransomware

Page 11: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Ransomware • Relatively new • Blocks ability to use computer • Encrypts data • Demands ransom to decrypt data • Payment in bitcoin • Increasing sophistication

– Cryptolocker, – Cryptowall (improved version of CryptoDefense) – Locky – CTB Locker

Page 12: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Subtle Signs of Infection

Page 13: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Cryptolocker

Page 14: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

FBI Ransomware (Credit: Corero Network Security)

Page 15: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Hydracrypt (Credit: Cyberwarzone)

Page 16: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

PRISM (credit: Thrive Networks)

Page 17: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Noteworthy Incidents (past month) • Hollywood Presbyterian Medical Center

– Ransomware attack – Paid $17,000 in bitcoin to decrypt files

• Lukas Hospital, Neuss, Germany – Computers, servers, email affected

• Klinikum Arnsberg, Germany – Only one server affected – Caught and restored in time

• Los Angeles County Health Department – Five computers, no damage to patient data

Page 18: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

How does it get into systems?

Page 19: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Primary Entry Points Include: • Fake virus detectors • Fake updates of real software • Flash • Silverlight • Word documents with macros • Spoofed emails • Attachments

Page 20: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Primary Enablers: • Employees • Habit • Play on emotions:

– Greed – Humor – Social interaction – Sense of community

• Lack of security focus throughout enterprise

Page 21: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Obstacles • Source difficult to trace • Will they actually unlock the data? • Even after decrypt, ransomware may remain (back for more?) • Backups may be infected • Becoming well-funded • Cost of entry low / reward high • Paying encourages activity • Easy access to “kits” • Most attacks generated remotely

Page 22: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

New Variants: Locky • Email appears to be a company invoice • Word Document with Macros • Mid February was spreading at 4,000 infections / hour

The Hacker News

Page 23: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Hacer News The Hacker News

Page 24: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

BleepingComputer tracked17K infections in one hour

Page 25: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

New Variants: Locky • Encrypts almost all file formats • Seeks out network and mapped drives to encrypt • Seeks out network BACKUP files to encrypt • Affected files have .locky extension • Seeks between $200 and $800 in bitcoins

The Hacker News

Page 26: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

New Variants: CTB Locker • One version is designed for servers • Attacks websites • Replaces the index.php or index.html page

The Hacker News

Page 27: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

The Hacker News

Page 28: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

New Variants: CTB Locker • Offers free decryption of two files

– 'Congratulations! TEST FILES WAS DECRYPTED!!‘ • Chat with the criminals about your files • Files added as part of the package known by researchers • Three servers used are known • Payment in bitcoin

The Hacker News

Page 29: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

New Variants: CTB Locker • Another version for Windows • Uses stolen authentication certificates • Easier to recover from with good backups

The Hacker News

Page 30: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

What to do? • Backups • Consider third party backups • Dedicated security team/department • Security is enterprise initiative • Educate employees • The Internet of Things opens many doors to attacks

– Medical devices – Specific attacks customized for healthcare

• Address any software/hardware vulnerabilities • Contact law enforcement / FBI

Page 31: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

“The healthcare sector is the most targeted yet underprepared genre within our Nation’s critical infrastructures.” – ICIT “Hacking Healthcare IT in 2016”

Page 32: Ransomware: The Secret is Out, Healthcare is Vulnerable · • 67% - Malware infections • 57% - HIPAA violations / compromised data • 40% - Internal vulnerabilities • 32% -

Thank you!

Rod Piechowski, MA Senior Director, HIS, HIMSS

[email protected]