UNCLASSIFIED // FOR OFFICIAL USE ONLY 18 March 2016

CIAC Report 16-07556

Colorado Information Analysis Center

****Situational Awareness**** (U//FOUO) Ransomware Disruptions to Hospital Operations Increasing (U//FOUO) Recently, hospitals have been infected with ransomware that has rendered patient files, equipment interfaces 1 and email unusable. The spread of this type of infection is increasing and will likely impact more hospitals. Hospitals also incur premium charges to resolve the issue and return to normal operations. (U/FOUO) Ransomware is a malware infection that is typically spread via infected email attachments. Once the infected 2 document is opened the virus encrypts files on the local machine and searches for available network drives to encrypt. This infection can rapidly render a large portion of a hospital network unavailable. Once the infection has taken hold users see a screen that warns of the incident, the cost (in bitcoin) to resolve and how to acquire bitcoin. USBUS

(U/FOUO) Hollywood Presbyterian Medical Center was forced to divert patients to other facilities, resort to paper records and fax machines for transmitting information and ultimately paid approximately $17,000 in ransom to recover 3 their systems. Other hospitals in North America and Europe have also fallen victim to this threat with varying degrees of 4 impact. 5

(U/FOUO) Ransomware operators usually charge approximately $400 to restore files. The $17,000 ransom demand to Hollywood Presbyterian Medical Center could indicate a progressive pricing scheme based on the success of the 6 infection. Both the malware and the tactics are expected to evolve making prevention and response more difficult. (U) In order to minimize operational risk, organizations may consider the following recommendations:  (U) Engage IT departments to consider the risk from this type of attack and potential mitigation.  (U) Review Continuity of Operations Plans for coverage of incidents that include lack of access to patient records, email and other network based services.  (U) Review Crisis Communication plans for possible implementation during this type of attack.  (U) Consider computer user awareness and security training specific to email use. (U//FOUO) This report addresses the following CIAC Standing Information Needs: CIAC-SIN-5, 11, 16. (U//FOUO) This report addresses the following CIAC CIKR: Sector 12.

1

(U) http://www.databreachtoday.com/fbi-warning-ransomware-surging-a-8962 (U) http://www.trendmicro.com/vinfo/us/security/definition/Ransomware 3 (U) http://www.digitaltrends.com/computing/hollywoodhospitalransomwareattack/ 4 (U) https://hacked.com/german-hospitals-targeted-in-ransomware-cybercrime/ 5 (U) http://www.idigitaltimes.com/new-locky-ransomware-virus-spreading-alarming-rate-can-malware-be-removed-andfiles-512956 6 (U) http://www.idigitaltimes.com/new-locky-ransomware-virus-spreading-alarming-rate-can-malware-be-removed-andfiles-512956 2

CIAC Customer Satisfaction Survey Please take a moment to complete this survey and help evaluate the quality, value, and relevance of our intelligence product. Your response will help us serve you more effectively and efficiently in the future. Thank you for your cooperation and assistance. Click here to take survey. For further information concerning this bulletin please contact the Colorado Information Analysis Center at (877) 509-2422 or email [email protected] To report suspicious activity, please visit our website at http://www.dshem.state.co.us

UNCLASSIFIED // FOR OFFICIAL USE ONLY 1 of 1

Production Number: 080067

CIAC 16-07556 Ransomware Disrupting Hospital ... - Drive

CIAC 16-07556 Ransomware Disrupting Hospital Operations_Mar2016.pdf. CIAC 16-07556 Ransomware Disrupting Hospital Operations_Mar2016.pdf. Open.

21KB Sizes 1 Downloads 94 Views

Recommend Documents

Ransomware eBook.pdf
Page 2 of 9. Tech experts say your next quarterly conference call could produce an unusual action item: extortion. If recent events are any indication, there's a ...

TA13-309A: CryptoLocker Ransomware Infections.pdf
There was a problem previewing this document. Retrying... Download. Connect more apps... Try one of the apps below to open or edit this item. TA13-309A: ...

CIAC%20Revised%20Rules%20of%20Procedure%20Governing ...
Try one of the apps below to open or edit this item. CIAC%20Revised%20Rules%20of%20Procedure%20Governing%20Construction%20Arbitration.pdf.

Handling Cyber Threats: Ransomware - Snell & Wilmer
Aug 28, 2017 - or locks a company's valuable digital files and ... software permits hackers to load malicious ... updated their software to install the patch.

Handling Cyber Threats: Ransomware - Snell & Wilmer
Aug 28, 2017 - James P. Melendres is co-chair of the Cybersecurity, Data Protection, and Privacy practice ... intelligence and gain control of systems on the.

Hospital Private.PDF
Jan 13, 2015 - Page 1 of 1. Hospital Private.PDF. Hospital Private.PDF. Open. Extract. Open with. Sign In. Main menu. Displaying Hospital Private.PDF.

DESUN HOSPITAL & History DESUN HOSPITAL ...
Page 1. Hospital. , in the modern sense of the word, is an institution for health care providing ... the expense being borne by the royal treasury. Stanley ... Larger cities may have several hospitals of varying sizes and facilities. Some hospitals,

backus hospital complaint.pdf
5 days ago - 2004) (claims with allegations of a breach of. contract or tort liability are pre-empted by § 301 if they are inextricably intertwined with the. collective bargaining agreement and require the court to interpret the terms of the agreeme

Hospital Network Design.pdf
Retrying... Download. Connect more apps... Try one of the apps below to open or edit this item. Hospital Network Design.pdf. Hospital Network Design.pdf. Open.

Hospital Administration - II.pdf
Download. Connect more apps... Try one of the apps below to open or edit this item. Hospital Administration - II.pdf. Hospital Administration - II.pdf. Open. Extract.

Worldwide "ransomware" cyber attack hit 74 ... -
conference, "Project Treble" is designed to reduce the burden on phone makers looking to ... Hacking group used leaked NSA tool for global cyber attack.

CIAC Revised Rules of Procedure Governing Construction Arbitration ...
Retrying... CIAC Revised Rules of Procedure Governing Construction Arbitration.pdf. CIAC Revised Rules of Procedure Governing Construction Arbitration.pdf.

CIAC Revised Rules of Procedure Governing Construction Arbitration ...
Republic of the Philippines ... Construction Industry Authority of the Philippines ... PDF File: Whisky In Your Pocket: A New Edition Of Wallace Milroy's The Origin ...

Tracking Ransomware End-to-end - Research at Google
runs on VirtualBox virtual machines (VMs); and Windows XP on a bare-metal machine. We opt for ..... 8.1. Locky. 7,825. 6,632. 84.8. 3,032. 38.7. 33.2. Spora. 827. 3. 0.5. 131. 15.9. 0.1. WannaCry. 100. 100. 99.4. 36. 36.5. 36.3. Using this pattern, i

Tracking Ransomware End-to-end - Research at Google
When the encryption completes, the ransomware displays a ransom note on the host's screen, informing the user that those files are held for ransom, payable in ...... file system, we place documents that Cerber is known to encrypt [11]. We also instru

PKD Valluvanad Hospital
[email protected]. Telephone No. Land Line 0466-2344900. 2244423. Mobile. FAX: 0466-2248869. Name of Nodal Officer /. Contact Person.

Bumrungrad Hospital - Settrade
Jan 3, 2018 - *The Company may be issuer of Derivative Warrants on these securities. http://research.kgi.com; Bloomberg: KGIT . Please see back ...

Bumrungrad Hospital - efinanceThai
Return on Avg. Equity (%). 27.2. 26.2. 28.7 .... Source: C om pany data, KG I Research ... per day. The com pany is one of the leading healthcare providers in.

The Future Hospital - IPPR
the journey to a good society is one that places social justice, democratic participation, and economic .... currently being played out in the media and in communities across the UK. In order .... The Future Hospital www.ippr.org 10 ...... with local

Bangkok Chain Hospital - SETTRADE.COM
Company Update | BCH. Krungsri Securities Research .... Income tax on company & subsidiaries. (159). (174). (228) ..... Renewable Energy. 662-659-7000 ext.