Site navigation

Conti Cyber-group Aid Irish Health Board Despite Data Release Threat

David Paul

,

Conti Cyber-group
Following last week’s attack, the hackers offered to aid recovery, whilst still threatening to release the data.

The Conti cyber-group, which was behind the major attack on the Irish health board, says it will release the encryption software for free after the attack.

The Health Service Executive (HSE) of the Republic of Ireland was crippled last week after a “significant ransomware attack” brought down its computer systems.

However, the group behind the attack have now handed over the software to regain access to IT systems in an apparent U-turn.

In a statement on its darknet website, it told the HSE that it would be providing the decryption tool “for your network for free”.

However, the Conti cyber-group has said it would still publish a lot of private data “if you will not connect us and try to resolve the situation”.

This has not stopped the hacking group from being the target of legal action. An Irish court has served an injunction on the hackers to prevent the Conti hacking group from leaking sensitive medical data.

Stolen data includes private medical information related to HSE patients, as well as payroll and HR data of its employees. The hackers have demanded $20m to restore the encrypted files.

In an interview with Irish broadcaster RTÉ, Irish Minister for Health Stephen Donnelly commented: “No ransom has been paid by this government directly, indirectly, through any third party or any other way. Nor will any such ransom be paid.

“It came as a surprise to us. Our technical team are currently testing the tool. The initial responses are positive.”

The attack, which comes a week after the major cyberattack that crippled the Colonial fuel pipeline in the US, has prompted concerns around the world about the strength of cybersecurity protection.


Recommended


Jamie Smith, Head of Cyber Security at S-RM, told DIGIT: “Conti is one of the most prolific groups currently operating. It has attacked over 50 organisations in April 2021 alone. Conti also has a track record of leaking data stolen from hospitals, having done it twice in February this year.

“Organisations and government alike are vulnerable to the ever-increasing problem posed by organised criminal groups conducting ransomware attacks. As public and private systems become more connected in the digital economy, ransomware becomes more and more lucrative for cybercriminals.

“Hospitals and other healthcare bodies are frequently seen as lucrative targets for extortion, thanks to the sensitive patient data they hold and critical medical services they deliver.”

Smith continued: “This attack on the Irish health system will hopefully prompt Ireland and other governments to follow the lead of the US, which is also this week recovering from the attack on the Colonial Pipeline. Further public and private cooperation will be crucial to fully address the indiscriminate and evolving threat of criminal ransomware groups.”

According to research by ExtraHop, more than two-thirds (67%) of organisations are still running an insecure Windows protocol largely responsible for the infamous WannaCry and NotPetya attacks of 2017 and 2018, continuing to put healthcare at risk.

Jamie Moles, Senior Security Engineer, ExtraHop, added: “Until investment is made in protecting IT Infrastructure these problems will continue to plague national healthcare providers worldwide.

“Healthcare systems need to keep up the momentum of IT improvements required for Covid related issues and harness it to progress from their current state”

David Paul

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data