35 ms·
Hospitals across England hit by large-scale cyber-attack
- sofaofthedamned 9y agolol https://twitter.com/GCHQ/status/863039131399663618 https://twitter.com/GCHQ/status/863039131399663618
- zigzigzag 9y agoClassic. GCHQ and NSA are joined at the hip. If telefonica are right and it's spreading through the NSA hacks revealed by the Shadow Brokers then GCHQ/5-eyes has some responsibility for what's been happening.
- sofaofthedamned 9y agoExactly. I'd hope something good would come out of this, i.e. no exploit hoarding by the NSA/CESG, but instead they'll double down and use it as a reason to remove even more of our rights online.
- a2decrow 9y agoAnd this is the reason why you don't centralize critical infrastructure and don't put yourself in vendor lock-ins. Makes me wonder how many of those infected machines didn't have to be connected to the internet in the first place.
- UK-AL 9y agoNHS isn't centralised. And not really locked in. NHS relies patch work of legacy software. Each trust and hospital handle I.T their own way. Which is why some are affected and some are not. So far it spread via file sharing and emails. The main issue is they don't patch, and update their stuff!
- jstanley 9y agoThe ransom from the address in the screenshot appears to have been paid: https://blockchain.info/address/12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw https://blockchain.info/address/12t9YDPgwueZ9NyMgw519p7AA8is... Here's another screenshot, with a different address: https://img.jes.xxx/1472 https://img.jes.xxx/1472 Also appears to be paid: https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNX...
- ryanlol 9y ago>Also appears to be paid: https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNX.. https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNX.... Appears to be paid twice in fact, honestly I'd bet that it's people paying these as a joke rather than the NHS.
- jstanley 9y agoIt's quite a lot of money to spend as a joke. And multiple payments could occur if the software has a pre-populated list of addresses rather than generating a new one for each infected machine. Of course, it could be the attacker sending money to himself to try to make victims think other people are paying.
- oh_sigh 9y agoA lot of people have a lot of bitcoin sitting around with no desire to cash out of it.
- ge96 9y agoI've started buying it every time I get paid from my wage_slave job. I don't know what to do with it. I mean some stores support it, and I found you can buy Amazon gift cards. It's not like you just "turn it into cash" and Xappo is not supported in the US. I realize there are alternatives. I don't have much anyway, but it's crazy! Worth more than gold. I wonder about that 4K $ value that someone estimated. I'm just buying for FOMO I guess.
- cronopios 9y agoTelefónica, the main telecommunications provider in Spain, is also hit. Employees were instructed to shut down their PC's and go home.
- haydenchambers 9y agoand Iberdrola and Natural Gas
- Cyph0n 9y agoDamn. I wonder how much money they lost due to the decrease in productivity.
- lottin 9y agoTechnically speaking productivity is amount of output per unit of time worked, working less time typically reduces both the numerator and the denominator so it doesn't necessarily affect productivity.
- ptaipale 9y agoBut this definitely impacts the production, i.e. the total amount of output.
- iagovar 9y agoOperations kept working, it just the office stuff that got down, and a bunch of web apps used to get status info on DSLAMS and bunch more subsistems. It is bad, but not as bad as a total disaster.
- aluhut 9y agoI'm sure some secret agency has backups of that data.
- sharemywin 9y agonot sure why the IT department wouldn't have a backup.
- rcarmo 9y agoMaltracker entry: https://maltracker.net/analysis/file/ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa/ https://maltracker.net/analysis/file/ed01ebfbc9eb5bbea545af4...
- MichaelGG 9y agoFor $300, even per machine, it seems like a cheap "mind your backup/restore system" lesson.
- Raphmedia 9y ago300 Bitcoin equals 524982.00 US Dollar Edit: Oh, it's indeed USD$300 in Bitcoin that is asked. Cheap!
- raverbashing 9y agoIt's not 300 bitcoin
- stestagg 9y agoThis could have been a shophisticated attempt to guess how much spare cash the NHS actually has these days
- k-mcgrady 9y ago>> $300, even per machine Plus potentially hundreds of cancelled procedures, including all electives for the next two days, cancelled GP appointments, etc. etc. The lesson is going to cost a lot more than $300 per machine (and as it's per machine that could end up being $300k per hospital when you consider the number of machines they have).
- MichaelGG 9y agoWhy would they have even anything close to 1000 machines storing data though? Not even sloppy, that just seems outright difficult to manage.
- k-mcgrady 9y agoI didn't consider the 'storing data' aspect as I'm not sure how the ransomware works. I thought it was taking each machine hostage (not just the networked storage).
- 9y ago
- crocal 9y agoThis is affecting pretty much all Europe. We are shutting down everything here: France, UK, Italy, Spain, Sweden, ...
- silverkity 9y agoSame attack happened in China. Most of the affected are college students.
- 6stringmerc 9y agoIn the aftermath I wonder if we'll ever find out how the attack was enabled. As in, who opened the attachment. My hunch? An Executive high enough in Leadership who won't get fired. Will be interesting to see.
- benjojo12 9y agoWhy would you fire someone for opening an attachment?
- teej 9y agoCyber security is everyone's responsibility. In the US at least, hospitals and their staff are held responsible for the proper care and handling of patient health data. In my opinion a hospital administrator should definitely be held accountable for poor computer practices that led to patient data being compromised.
- DanBC 9y agoAccountability after an event does little to prevent future events. There's a lot of focus on human factors in the NHS, and that tends to avoid things like blame.
- emodendroket 9y agoThe rational response in such a system if you mess up is to not tell anybody, wait, and hope the problem gets bad enough that it's not obvious where it started.
- pasquinelli 9y agothat's a good question, but it's totally independent of the expectation that if it was some low-level nobody who did it then their ass'd be fired.
- emodendroket 9y agoThey probably wouldn't. I'm sure anybody who's been a sysadmin has seen this happen.
- lol768 9y agoShutting everything down seems like a really rash response, especially when these systems seem to be used for critical communication e.g. the phones too. The Twitter messages seem to suggest that doctors are seeing this on their personal machines, but why would this impact the phone system? Are they not separated out? I'm also really curious as to how this started. The article mentions a "bug" in the IT systems - some sort of novel zero day in the software they're using that was exploited remotely? Or is it more likely someone screwed up and ran something without thinking? Edit: There are reports on twitter that this is impacting X-rays, pagers as well as the phone system. This is ridiculous if true and suggests there have been some major failings when putting this infrastructure in place.
- FLUX-YOU 9y ago>There are reports on twitter that this is impacting X-rays, pagers as well as the phone system. This is ridiculous if true and suggests there have been some major failings when putting this infrastructure in place. Take a look at that operating system and the UI from the article and tell me how that's unexpected.
- alex_hitchins 9y agoThat will be stock photography, rather than taken today.
- FLUX-YOU 9y agoIt is still accurate. We still have XP machines floating around our campus. They are running EMR software.
- lol768 9y agoAre they paying Microsoft for extended support?
- alex_hitchins 9y ago
- noxToken 9y agoCaught wind of this earlier today with a European client. We were advised to not connect to their network via VPN. Looks like it's a large scale attack that's affecting more than just hospitals in England. These could be a coincidence though. Here is a source article talking about a Spanish TelCo: https://www.usnews.com/news/technology/articles/2017-05-12/spanish-companies-hit-by-ransomware-cyber-attack https://www.usnews.com/news/technology/articles/2017-05-12/s...
- crocal 9y agoIt is large scale all across Europe. NHS is only one among many (we are smack in the middle of it)
- TomK32 9y agoLike the NHS didn't have enough problems with unhappy staff, unfilled positions and Brexit looming... very uncool.
- lol768 9y agoExisting discussion thread: https://news.ycombinator.com/item?id=14324129 https://news.ycombinator.com/item?id=14324129 --------- Shutting everything down seems like a really rash response, especially when these systems seem to be used for critical communication e.g. the phones too. The Twitter messages seem to suggest that doctors are seeing this on their personal machines, but why would this impact the phone system? Are they not separated out? I'm also really curious as to how this started. The article mentions a "bug" in the IT systems - some sort of novel zero day in the software they're using that was exploited remotely? Or is it more likely someone screwed up and ran something without thinking? There are reports on twitter that this is impacting X-rays, pagers as well as the phone system. This is ridiculous if true and suggests there have been some major failings when putting this infrastructure in place. Perhaps underinvestment in IT is to blame.
- s_kilk 9y ago> Perhaps underinvestment in IT is to blame. Or, indeed, over-investment in trash-tier IT services provided by blood-sucking IT consulting companies. I've seen the insides of some UK Government IT systems (not the NHS), and it's astonishing how little functional software one can get in exchange for a few hundred million sterling. That, and the bitrot of holding on to ancient, never-updated IT systems. [Edit], back on topic, I sincerely hope whoever did this is burned alive for their crimes.
- rubatuga 9y agoThe whole EHR market is absolute crap in Canada too. You have around 10 competing standards with no interoperability, multiple data sources cobbled together through webpage links, and all running on a slow as fuck central server that you Citrix into. Another research department I worked at was seriously underfunded, which resulted in questionable decisions, such as using round cube for email, and a central shared drive with a Microsoft access database containing patient data. Hospitals have terrible security.
- jensv 9y agoWhat is the issue or alternative to Roundcube? I thought they were pretty good.
- dberhane 9y agoThe BMJ published an article recently about hackers targeting hospitals, "The hackers holding hospitals to ransom": http://www.bmj.com/content/357/bmj.j2214 http://www.bmj.com/content/357/bmj.j2214
- la_oveja 9y agoSpanish big companies like Telefonica, Inditex, Iberdrola, Endesa... are being attacked too. Seems serious.
- pcardoso 9y agoSome portuguese too: EDP, PT and NOS...
- nathanlied 9y agoI've heard from some people in Portugal that MEO is affected, as well as the Spanish Vodafone. A friend working for the Portuguese Vodafone is saying that, so far, they're unaffected. This seems to be quite serious.
- kaoD 9y ago300$ ransom doesn't seem like they're being targetted. The virus just spreads very, very well through corporate (i.e. Windows) intranets, including when connecting through a VPN, using a remote code execution vulnerability (see my other comment here https://news.ycombinator.com/item?id=14324592 https://news.ycombinator.com/item?id=14324592). Considering it's already hit some tech giants, it was just a matter of time until it spread through their VPNs to their workers, clients and beyond. This is gonna be fun to watch from the sidelines.
- jjgreen 9y agoSounds like ransomeware https://twitter.com/asystoly/status/863027172453351424 https://twitter.com/asystoly/status/863027172453351424
- factsaresacred 9y agoSeems like non-targeted ransomware - https://twitter.com/ShaunLintern/status/863032223469056004 https://twitter.com/ShaunLintern/status/863032223469056004 - based on the modest $300 request. Note: I've zero idea if that screenshot is legit but it's posted on The Health Care Journal website so it likely is. Edit: - Earliest Google result for "WanaDecryptor" is from Aug 2015 (All other search results are from today): > almost all of the files on the D drive is encrypted. C is not touched by the disc. file found is in the ProgramData folder, there is a hidden folder, the virus in it. When you delete a folder that is created again and the process starts again. http://www.cyberforum.ru/viruses/thread1979411.html http://www.cyberforum.ru/viruses/thread1979411.html http://www.cyberforum.ru/viruses/thread1979358.html http://www.cyberforum.ru/viruses/thread1979358.html - Discussion from today mentioning it infecting Spanish Telecoms: http://gta-trinity.ru/forum/index.php?/topic/57671-novejshij-virus-na-pk/ http://gta-trinity.ru/forum/index.php?/topic/57671-novejshij....
- brightball 9y agoAt a security seminar last year I got to hear an expert talk about tracking down ransomware over the course of a couple of years. He said, no matter what the value of bitcoin the price gets adjusted to be equivalent to $300. That is the presumed sweet spot where people realize it's worth the money to save their data.
- jgrahamc 9y agoFriend of mine who works for the NHS sent me the following email: All of NHS PCs and hospital systems have gone down from a ransomware trojan! I have a full clinic this afternoon, and no way to look at my patients' histories, or meds. It's a damned disgrace. The Trojan is demanding some bitcoins be paid, else they'll lose the boxen. The entire NHS is penetrated. I can't vouch for "the entire NHS is penetrated"
- narrator 9y agoSometimes I wonder how much of the economic activity in bitcoin is generated by ransomware.
- ruiquelhas 9y agoI'm pretty sure it is a really good chunk. Probably only trumped by drug deals.
- notadoc 9y agoWow that sounds bad.
- mr_spothawk 9y agohmmm... that doesn't sound like a 'cyber attack' as much as it sounds like 'getting owned by a trojan'
- nthcolumn 9y agoA 'coordinated' attack apparently unless it is a very agile worm, lots of disparate unconnected levels being hit - such as GP surgeries (local clinics) to large hospitals A&E (ER). The common factor being the widescale abuse of @nhs.net as the email provider for all. Local GPs not meant to be using it at all.
- throwaway049 9y agoWhat is the reason local GPs are not meant to use NHS.net email? I work in the sector and I thought it was policy to have them use it as the approved platform to securely communicate with secondary care.
- frereubu 9y agoThe NHS is notorious for using outdated software, so I'm surprised it's taken so long. We build websites for third-sector organisations who often deal with the NHS and we're only just now persuading them to drop support for Windows XP / IE8.
- petepete 9y agoYeah, I left the NHS in 2009 after much frustration in trying to implement modern(ish) replacements for various reporting systems. Every idea was discussed and watered down until what's left was neither use nor ornament. There are many great and extremely dedicated employees but the vendor lock-in has painted them into many (disparate) corners.
- pjc50 9y agoNHS IT is, of course, vastly under-funded compared to even modest startups, and entangled in bureaucracy of upgrades. I used to work with someone who was one of two sysadmins for a hospital of several thousand staff.
- kristianc 9y agoThis is partly a consequence of the NHS Connecting for Health debacle, which on an original budget of £2.3 billion managed to hit a projected cost of £12.4bn with almost nothing to show for it apart from a patchy implementation of Choose and Book. https://en.wikipedia.org/wiki/NHS_Connecting_for_Health#Costs https://en.wikipedia.org/wiki/NHS_Connecting_for_Health#Cost...
- petepete 9y agoBooze and Chuck, for the uninitiated.
- shubb 9y agoNHS systems are remarkably un-integrated. Communication, especially between trusts and external organisations like GPs, is often by email. I'll be surprised if this isn't an email worm.
- soVeryTired 9y agoThey had a fiasco in November by sending an email org-wide which had "reply-all" enabled. So they clearly don't follow best practice. http://www.bbc.co.uk/news/technology-37979456 http://www.bbc.co.uk/news/technology-37979456
- adv0r 9y agothe same is happening in spain https://www.ccn-cert.cni.es/seguridad-al-dia/comunicados-ccn-cert/4464-ataque-masivo-de-ransomware-que-afecta-a-un-elevado-numero-de-organizaciones-espanolas.html https://www.ccn-cert.cni.es/seguridad-al-dia/comunicados-ccn...
- rjtavares 9y agoAnd Portugal, affecting telecom companies (confirmed by the cybercrime unit of the police): https://www.publico.pt/2017/05/12/tecnologia/noticia/ataque-informatico-internacional-afecta-empresas-e-hospitais-1771939 https://www.publico.pt/2017/05/12/tecnologia/noticia/ataque-...
- adv0r 9y agolook at what is happening in spain Telefonica giant
- myaccountzz 9y agoOh the irony, the NHS has been holding the tax payers ransom since the '40s.
- oneeyedpigeon 9y agoHere in the UK, that is an incredibly unpopular opinion. I've never met anyone who isn't in favour of the NHS.
- spoovy 9y agoYou should get out more, I know loads of them.
- nthcolumn 9y agoBest value for money health service in the world absolutely no contest. Free healthcare for all no questions asked. Sounds like some johnny foreigner to me. Probably a Trump supporter chiming in with his alternative facts. Even he can get treatment here. I'm not so sure about a cure.
- throwaway049 9y agoThe NHS does charge people who are not permanently and lawfully resident in the UK. https://www.gov.uk/government/publications/guidance-on-overseas-visitors-hospital-charging-regulations/summary-of-changes-made-to-the-way-the-nhs-charges-overseas-visitors-for-nhs-hospital-care https://www.gov.uk/government/publications/guidance-on-overs...
- EnderMB 9y agoSadly, I think there are more people that would be in favour of a private system than we'd like to admit. A lot of people have bought into the Tory idea that the NHS is unsustainable, and that the reason we're all poor is because we're paying for what they see as sub-par care. On one side, the NHS is arguably the greatest success story of the UK, and I think many people would riot if their free healthcare was taken away. On the other, people will happily vote against a party that is looking to increase its funding, and will happily vote for a party that has made significant moves to privatise our healthcare system, so logically there must be people that aren't in favour of the NHS.
- BillFranklin 9y agoOn the other hand, $300 sounds like a bargain.
- kaoD 9y agoPer computer. If the ransomware has no vulns itself, this is going to be a hit to economy, either by paying the ransom (it's already hit some major companies) or the losses produced by it.
- BillFranklin 9y agoThank you, I didn't see that.
- gtsteve 9y agoI should hope that they can just reimage the workstations and if network drives were affected, just restore from shadow copy or backups.
- kaoD 9y agoYou can reimage the workstations but how much work has been lost? Probably an awful lot. I can't even fathom how many spreadsheets with no backup have been lost today. WRT backups... :^)
- jermaustin1 9y agoI've rarely worked at a place that didn't shadow copy your user directory to a network location. The only thing that SHOULD be lost is whatever hadn't been saved when they were ransomwared. The company should be able to pull a backups from the last file change prior to that event.
- Nexxxeh 9y agoHas anyone paid this specific ransom and had their files decrypted? I've got a client who is infected. A member of their staff has now left for a holiday, this is a nightmare. I'm loathed to have them pay the ransom, but restoring from the last backup will cost vastly more in work product and business impact than the cost of the ransom.
- uxhacker 9y agoThis must be a new virus. It is hitting Spanish and Portugese Telecoms.https://www.usnews.com/news/technology/articles/2017-05-12/spanish-companies-hit-by-ransomware-cyber-attack https://www.usnews.com/news/technology/articles/2017-05-12/s... http://sicnoticias.sapo.pt/pais/2017-05-12-PT-Vodafone-EDP-e-KPMG-alvo-de-ataque-informatico http://sicnoticias.sapo.pt/pais/2017-05-12-PT-Vodafone-EDP-e... (Portuguese) The worrying part is distribution and essencial companies and services
- ojosilva 9y agoThis is apparently part of coordinated ransomware campaign targeting large corporations in Europe, only a few of which are making the news at this time. Some other links: https://www.ft.com/content/74c666ec-8dc7-3b20-b573-245bc0e9d935 https://www.ft.com/content/74c666ec-8dc7-3b20-b573-245bc0e9d... http://www.impala.pt/noticias/pt-alvo-ataque-informatico/ http://www.impala.pt/noticias/pt-alvo-ataque-informatico/ [PT]
- jlebrech 9y agothe NHS is suffering from a human denial of service attack from old people, drunks, immigrants that haven't had immunisation, congenital diseases, fgm, etc.
- objclxt 9y agoWhat proportion of costs do you think "immigrants that haven't had immunization" and "fgm" represents in the NHS versus "old people"? Here's a hint: a rounding error.
- nthcolumn 9y agoYeah 'old' people because y'know you don't want to look after them do you?? Screw old people... and the sick.
- sctb 9y agoPlease don't post uncivilly like this. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- kaoD 9y agoAccording to Spain's CCN-CERT it's spreading through a remote code execution vulnerability in Windows' SMB Server, affecting pretty much all versions of Windows. https://www.ccn-cert.cni.es/seguridad-al-dia/comunicados-ccn-cert/4464-ataque-masivo-de-ransomware-que-afecta-a-un-elevado-numero-de-organizaciones-espanolas.html https://www.ccn-cert.cni.es/seguridad-al-dia/comunicados-ccn... https://technet.microsoft.com/en-us/library/security/ms17-010.aspx https://technet.microsoft.com/en-us/library/security/ms17-01... IIUC the security updates have been available since March. I can understand bureaucratic entities having shitty security policies, but Telefónica? It's just... wow.
- sofaofthedamned 9y agoThere are parts of the NHS who specifically do not patch.
- ajross 9y agoAnd hopefully they have well-designed and regularly audited firewalling and access control paradigms. There are good reliability reasons behind not just sucking down every patch, but it needs to be coupled with smart security work. And in any case that doesn't seem to be the issue here, per reporting. It's not NHS's reliability-critical systems that are owned, it's all their PCs.
- sofaofthedamned 9y agoI'd hope so, too, but in what i've seen it generally isn't the case.
- walshemj 9y agoWhich they use to communicate between staff. I was at a renal clinic this afternoon and the staff there couldn't check to see if my doctor wanted them to do some bloods - so I can go back onto the transplant list. If I am unlucky this means I could miss out on a potential doner kidney due to the delay
- mjevans 9y ago
- amiga-workbench 9y agoWhy the hell do they need thick Windows boxes to handle patient records, would a dumb terminal not do and be far more resistant to this kind of problem.
- H1Supreme 9y agoThey don't need them, at all. Every business and organization that isn't using CAD or Photoshop or some other CPU / Memory intensive software could get by on thin clients alone. No problem. Secondly, how the hell are these records being stored? These viruses usually search for pdf,jpeg,doc, and xls files. Is patient data in spreadsheets and word docs? I don't get it.
- kalleboo 9y agoWindows + Web Browser is the "dumb terminal" of the 2010's.
- cjrp 9y agoI wonder how many of these systems have already been exploited (silently) in order to extract things like patient details? Scary.
- alva 9y agoBitcoin address transactions https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNX... https://blockchain.info/address/1QAc9S5EmycqjzzWDc1yiWzr9jJLC8sLiY https://blockchain.info/address/1QAc9S5EmycqjzzWDc1yiWzr9jJL... https://blockchain.info/address/13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 https://blockchain.info/address/13AM4VW2dhxYgXeQepoHkHSQuy6N...
- watbe 9y agoThe BBC have tweeted a screenshot[1] showing another address as well, showing a lot of activity at the address[2] 1: https://twitter.com/BBCBreaking/status/863046075002884097 https://twitter.com/BBCBreaking/status/863046075002884097 2: https://blockchain.info/address/13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 https://blockchain.info/address/13AM4VW2dhxYgXeQepoHkHSQuy6N...
- r3bl 9y agoFor those wondering, while I'm writing this, these Bitcoin addresses store $7771.84 (according to XE).
- deleted 9y ago[deleted]
- jasonkostempski 9y agoThis recently happened to a hospital in Buffalo NY: http://www.wgrz.com/news/local/ecmc-still-fixing-computer-system-problems/431724954 http://www.wgrz.com/news/local/ecmc-still-fixing-computer-sy...
- mvdwoord 9y agoAfter 20 years in IT, listening to all the bullshit by "Management" about "Audits" and "accepting the risk", "lessons learned" and whatnot. Honestly, I would be glad if a high impact issue like this, would change any of that for the better. I am unfortunately also a cynic (after 20 years in, well anywhere really) so I doubt it will. This means it will only negatively impact people who need the healthcare, and a bunch of consultants will make millions on sweeping up the mess, and creating the next failure-to-be. I'm making popcorn.
- madez 9y agoI've also become a cynic. I welcome national services to lose control of their systems and their data. I have had countless talks with people here in Germany about why computers and therefore open and libre software and hardware are a matter of national interest. Obvious disaster, at least and last, will hopefully make them get what I mean. Having said that, I feel bad, but I just don't see any other way.
- k-mcgrady 9y ago>> I've also become a cynic. I welcome national services to lose control of their systems and their data. Quite a moronic point of view when lives could be potentially put at risk.
- madez 9y agoI agree as to that it sounds moronic. Maybe it even is. However, think about a levee about which you know that it will not hold when a storm comes, but people don't believe you and are not even willing to listen to you. Would you think it's moronic to welcome a storm as a shot across the bows so people realized what you are talking about? The constructive solution to this problem is to find a way to convey the message such that people are willing to listen. But that can be very difficult.
- graphitezepp 9y agoIn a similar vein Karl Marx is said to have been pro free trade, as it would lead to what he believed would happen to capitalism much faster. Also the colloquial expression "kick in the teeth". Often actual change requires drastic consequences.
- fasinfranco 9y agoMaybe related to the cyber attack on Telefonica? http://www.elmundo.es/tecnologia/2017/05/12/59158a8ce5fdea194f8b4616.html http://www.elmundo.es/tecnologia/2017/05/12/59158a8ce5fdea19...
- fauigerzigerk 9y agoAs a quick reminder, here's the list of organisations (in addition to police and security services) that have (or will have) access to all internet connection records without a warrant according to the Investigatory Powers Bill: NHS trusts and foundation trusts in England that provide ambulance services Department of Health NHS Business Services Authority NHS National Services Scotland Health and Safety Executive Scottish Ambulance Service Board Scottish Criminal Cases Review Commission Northern Ireland Ambulance Service Northern Ireland Fire and Rescue Service Board Welsh Ambulance Services National Health Service Trust Home Office Ministry of Justice HM Revenue & Customs Department for Transport Department for Work and Pensions Competition and Markets Authority Department for Communities Department for the Economy Department of Justice (Northern Ireland) Financial Conduct Authority Fire and rescue authorities under the Fire and Rescue Services Act 2004 Food Standards Agency Food Standards Scotland Gambling Commission Gangmasters and Labour Abuse Authority Information Commissioner Health & Social Care Business Services Organisation Office of Communications
- sctb 9y agoUsers probably flagged this for being off topic. If you have a point about the NHS being one of these organizations that relates to the topic at hand, please make it directly—it helps prevent the discussion from slipping into more generic indignation.
- fauigerzigerk 9y agoApparently some people haven't been following the debates around the introduction of that law very closely. Less than stellar computer security at some of these organisations was one of the major concerns, and this incident shows that these warnings are clearly justified. I would have thought my point to be glaringly obvious. Perhaps rather than for being off-topic my comment may have been flagged because some don't like to hear "told you so" right in the middle of an incident that affects many people in quite dramatic ways (operations cancelled) and I can understand that. So I apologise for the insensitivity.
- DanBC 9y agoNHS Digital have released a comment: https://www.digital.nhs.uk/article/1491/Statement-on-reported-NHS-cyber-attack https://www.digital.nhs.uk/article/1491/Statement-on-reporte... ===begin quote=== A number of NHS organisations have reported to NHS Digital that they have been affected by a ransomware attack which is affecting a number of different organisations. The investigation is at an early stage but we believe the malware variant is Wanna Decryptor. At this stage we do not have any evidence that patient data has been accessed. We will continue to work with affected organisations to confirm this. NHS Digital is working closely with the National Cyber Security Centre, the Department of Health and NHS England to support affected organisations and to recommend appropriate mitigations. This attack was not specifically targeted at the NHS and is affecting organisations from across a range of sectors. Our focus is on supporting organisations to manage the incident swiftly and decisively, but we will continue to communicate with NHS colleagues and will share more information as it becomes available. Notes to editors As at 15.30, 16 NHS organisations had reported that they were affected by this issue. ===end quote=== I'd be interested to know how many patients are under the care of those 16 organisations.
- martindevans 9y agoDo we know which 16 are affected?
- DanBC 9y agoI don't. It's frustrating - I have no idea if these are tiny hospital trusts or a massive CCG or massive multi-county trusts.
- walshemj 9y agoIts now up to 33! and an individual trust covers a large area and several hospitals
- Animats 9y agoThe parent article does not use the word "Microsoft".
- pyrale 9y agoAnd I thought the tories were tech illiterates... they sure have improved!
- matthewdrussell 9y agoNo, just the odd HN user
- Asdfbla 9y agoIf only intelligence agencies spent as much money and effort on securing its critical systems as they invest in sabotaging other countries' infrastructure. Maybe putting defense first would be helpful, especially considering how easy the proliferation of offensive tools is.
- crocal 9y agoIt's a large scale attack impacting many companies. We are under attack and are shutting down everything here: France, Spain, Italy, UK, Sweden, ...
- peteretep 9y agoI guess it's only a matter of time until patient records are available.
- ziikutv 9y agoSomething like this also happened at Carleton University, but they did not pay the ransom. I assume they just used backups. They have really good (and super nice) IT people.
- corpMaverick 9y agoHow long until paying ransom for a cyber attack becomes a crime ?
- watty 9y agoI don't know, how long will humans exist? It will never be a crime.
- corpMaverick 9y ago"What I will argue is that when looking at a public policy problem, the best place to create liability is where it will have the desired impact. If the goal is to stop ransomware attacks, raising the costs of paying ransoms beyond what the criminals are demanding is the best way to do that." http://blogs.cfr.org/cyber/2016/02/29/paying-ransom-on-ransomware-should-be-illegal/ http://blogs.cfr.org/cyber/2016/02/29/paying-ransom-on-ranso...
- EternalData 9y agoIt seems like for that amount of money, you could have tried doing a bug bounty instead :/ I get that this is probably social hacking/phishing, so not really analogous -- but I wonder if there's a way to apply that kind of mentality to good. I wonder if there's white hat phishing (though I guess that might be oxymoronic).
- user5994461 9y agoThis is really fun to see two ransom threads on top of HN. This one asking for $300 to the NHS and the other one asking for $600 000 to a phone provider. Either the criminals have no idea what the NHS is or $300 is the limit of what middle managers can pay without much approval.
- jerf 9y agoIt's almost certainly simply a widely-targeted email that was "intended" to hit individuals via mass spam that happened to hit the wrong individual (who is probably having a Very Bad Day now) and took down the NHS. And my "almost certainly" is really just my inner engineer hedging; the fact that they're asking hundreds of euros worth of ransom for so much is basically proof of what I said. Unfortunately, the state of security right now is such that these wide-band transmissions can still pick up a lot of hits.
- nayuki 9y agoFor reference the other thread is https://news.ycombinator.com/item?id=14325380 https://news.ycombinator.com/item?id=14325380 "Telefonica Is Target of $600,000 Bitcoin Ransomware Attack"
- Nadya 9y ago>Hackers are demanding a payment of $300 per machine, roughly equal to 300 Bitcoins currently worth around 510,000 euros. Same cost for Telefonica - just "per machine".
- Animats 9y agoHow is this attack being distributed? It can't take much user involvement, or it wouldn't be hitting large numbers of systems that only run in-house applications.
- fourthdwarf 9y agoIt looks like it was MS17-10/EternalBlue, or at least that's what twitter is saying. https://twitter.com/AdamTheAnalyst/status/863040924783345665 https://twitter.com/AdamTheAnalyst/status/863040924783345665
- djsumdog 9y agoSo we should build backdoors into encryption to prevent this, right? /s
- n3storm 9y agoSpanish biggest telecom and others had been hit too: http://www.elmundo.es/tecnologia/2017/05/12/59158a8ce5fdea194f8b4616.html http://www.elmundo.es/tecnologia/2017/05/12/59158a8ce5fdea19... WannaCry ramsoware is the culprit.
- ge96 9y agoDoes it not make sense to have a "sub-layer" a local network of files rather than files being accessible by outside. I guess once "something" is in, like that Iran Stuxnet PLC attack, then it's inside and can execute from within. Unless it's like a local attack whether by a worker or something like found a thumb drive outside, plugged it into my work computer. not my field
- rdiddly 9y ago"There is no evidence patient data has been compromised, NHS Digital has said." Um, doesn't "encrypted beyond your reach" fall somewhere under "compromised?"
- iak8god 9y agoWell, hopefully they have backups, but the point of this statement is to reassure everyone that patient data has not been leaked.
- LinuxBender 9y agoRansomware is doing a good job of partitioning sensitive data from those that should not be (mis)managing it.
- mark_l_watson 9y agoTwo weeks ago I contacted my Congressman explaining how important encryption and general IT security is. While he said he agreed with me in principle, he said that terrorism is such a huge problem that things like back doors, weaker encryption, etc. are more important than strong encryption and general IT security. His reply was lengthy, but didn't say what I wanted to hear.
- deleted 9y ago[deleted]
- OliverJones 9y agoHey, this congresscritter actually answered. You have it on record saying something that may haunt it. My congresscritter ignores that kind of missive.
- mjevans 9y agoThis would be a good time to follow up. Point to the real world example of how in the real world terrorists, foreign nations, etc can and will use the backdoors for FAR more evil than they could ever do good.
- dredmorbius 9y agoI'm aware of a number of people pushing for similar types of initiatives, though I don't know of a combined effort. Word I've heard is that working through the DC office liason is probably the more effective route.
- LinuxBender 9y agoRansomware is doing a good job of partitioning sensitive data from those that should not be (mis)managing it.
- GedByrne 9y agoIt says the attack hit multiple sites simultaneously. A worker said that the ransomware came through on the computers around 2pm. This doesn't sound like a spread by phishing or attachment. How could such an attach be co-ordinated? I can think of two possibilities: 1) The attack has been spreading over days or weeks with a trigger date for activation. 2) The ransomware has been distributed through the desktop update system. Any other ideas?
- detaro 9y ago3) The internal networks are open enough that something worm-y can rapidly spread through bugs in common services (file shares or something like that), once it has infected one internal machine through some other channel.
- justforFranz 9y agoI wonder what the odds are that an attack on infrastructure like this could kill someone?
- astrodust 9y agoI honestly do not care if people use a proprietary closed-source operating system, but it freaks me out on an existential level that important things that might kill you are closed source. Life support machines, x-ray machines, heart-rate monitoring machines, even voting machines. Nobody knows what's going on in there, and a software fault or hack could be the end of you. Like that Toyota "unintended acceleration" bug which would've been discovered a lot sooner had other people been looking at the code. This is also coupled with the fact that these vendors, for reasons that challenge the absolute limits of my comprehension, insist on using old versions of Windows. I would not be surprised if equipment of that sort sold today still runs unpatched versions Windows XP. ATMs and cash-registers are likewise a total farce. Some of them are packaged so poorly it should be criminal.
- synotna 9y agohttps://en.m.wikipedia.org/wiki/Therac-25 https://en.m.wikipedia.org/wiki/Therac-25
- astrodust 9y agoEvery time I go through one of the airport scanners I think about that particular event. Who knows if an intern forgot to convert properly and the thing spews out a million times more radiation than intended.
- joosters 9y agoVery high. The disruption caused delayed countless operations, ambulances and GP visits. People will have missed vital medical assistance as a result, and that could easily be fatal.
- fencepost 9y agoSomething like this (though I don't know if it was targeted or a combination of luck+poor procedures) took down > 400 medical practices hosted by Greenway a few weeks ago. Some were down for as much as 9 days, and at day 11 I know of one that still didn't have access to their scanned documents. Greenway had backup procedures in place, but they were file-based - backing up databases, transaction logs, files, etc. and able to restore them onto a new server image as required. The problem arose when they had to do that for hundreds of customer servers at once. One of my customers knew there was a big problem when she signed onto their server (Intergy On Demand, hosted by Greenway, accessed via RDP) and saw ransom icons on the server desktop.
- crocowhile 9y agoI think the most interesting aspect of all this is that it's a clear evidence that even machines possessing highly sensitive data (like NHS computers) are super vulnerable to any remote penetration. The request for a ransom may just be the tip of the iceberg here.
- scholia 9y agoI think it's just evidence of a decrepit IT system. They were caught because they were running Windows XP with inadequate or no anti-virus software. They would not have the problem if they'd been running patched Windows 7. Microsoft fixed the vuln in March.
- easilyBored 9y agoNHS in England hit by 'cyber-attack' with ransomware demanding $300 in Bitcoin Excuse us but we just found out that you're NHS. Please make it $300,000 or else. Asking for just a little is a pretty good tactic, used by these guys, patent trolls and the mafia for protection money.
- devrandomguy 9y agoI would be interesting in finding a medical doctor's or a biologist's perspective on this. Suppose we consider the NHS to be a body, in the greater environment of the internet/economy/government. What traits of that environment led to the evolution of this ransomware pathogen? Now that we have had a massive, but not lethal exposure to it, how can we build up an immunity? What changes to the environment would eliminate the refuges of this pathogen?
- titanomachy 9y agoIt's like when smallpox was brought to the New World... the NHS's internal IT, existing in isolation, hasn't developed immunity to pathogens which are common elsewhere (i.e. they stopped installing Windows security updates). There may be certain mission-critical, non-internet-connected machines for which it's still safer not to install updates, but for the average doctor's workstation it will probably become the norm to install Windows patches. Where I live, doctors have more freedom in how they run their clinics and IT. That probably causes its own problems, but at least they're free to run a modern version of their OS and keep it patched. This kind of virus wouldn't affect us the same way since there's no top-down tech policy which prevents individual doctors from following good security practices; in fact, if you just follow all the recommended settings when installing Windows/macOS, you'll end up with automated patching by default. So if you really want an epidemiological analogy, maybe the best one is a monoclonal, monoculture crop (e.g. the Gros Michel banana) being decimated by a pathogen which has just evolved the ability to infect it: take down one banana, and you take them all. Take down one English doctor's computer...
- clydethefrog 9y agoA Dutch news article is claiming that ransomware can be fixed by "big IT security companies". [1] I thought there was no fix to these cyber-attacks unless you have a backup. I am interested how any fixes are possible? [1] http://nos.nl/artikel/2172840-waarschuwing-voor-grote-internationale-gijzelsoftware-campagne.html http://nos.nl/artikel/2172840-waarschuwing-voor-grote-intern...
- r721 9y agoKaspersky Lab's Analysis: https://securelist.com/blog/incidents/78351/wannacry-ransomware-used-in-widespread-attacks-all-over-the-world/ https://securelist.com/blog/incidents/78351/wannacry-ransomw...
- jumpkickhit 9y agoHow do these things decrypt? Couldn't someone take the "already paid" bitchain address from someone else, put it in and click "paid" with that to unlock it?
- boznz 9y agoStrange question but why is this data in file-systems and not on SQL/Cloud systems?
- DanBC 9y agoHere's a list of the trusts / etc that are affected. https://twitter.com/ShaunLintern/status/863116822228422656 https://twitter.com/ShaunLintern/status/863116822228422656
- lumberjack 9y agoThis is probably the first major hacking incident that will cause multiple deaths.
- tonmoy 9y agoHow can I protect myself from these NSA level attacks (not attacks by NSA, but by criminals who now have these tool)? Is keeping Windows up to date enough?
- genericacct 9y agoSurely just a coincidence that BTC reached a new all time high today ?
- politician 9y agoIs it not a form of malpractice by these hospitals to be running medically critical services on obsolete unsupported devices?
- mobiplayer 9y agoIf I were CEO of one of the big companies I would fire the CIO for not tracking critical patching and I would later resign for not making him/her accountable until now.