Site navigation

NHS Ransomware Attack: Hack Could Take Four Weeks to Fix

Michael Behr

,

NHS ransomware attack
Since being struck a week ago, Advanced has increased the timeframe for recovery, raising concerns about the extent of the attack.

The recent cyber-attack on the NHS has been confirmed as ransomware, the affected company has stated.

The attack targeted UK company Advanced, which provides and runs a variety of software and services for the NHS.

Among its affected software are clinical patient manager Adastra, care home manager Caresys and patient record software Carenotes. The company said that the issue was contained to 2% of its health and care infrastructure.

When news of the attack first broke, the company’s COO Simon Short predicted that the attack would be resolved this week.

However, a recent update from Advanced has warned that it could take three to four weeks for it to recover from the NHS ransomware attack.

“We are rebuilding and restoring impacted systems in a separate and secure environment,” a company statement read.

The ransomware struck Advanced’s systems on August 4th, affecting services across all four of the UK’s nations.

While the NHS and Advanced have said that the disruptions have been minimal, NHS 111 and ambulance dispatch systems suffered disruptions, and staff were left struggling to make out-of-hours appointments and issue emergency prescriptions.

“While Advanced has confirmed that the incident impacting their software is ransomware, the NHS has tried and tested contingency plans in place including robust defences to protect our own networks, as we work with the National Cyber Security Centre to fully understand the impact,” an NHS England spokesperson has said.

“The public should continue to use NHS services as normal, including NHS 111 for those who are unwell, although some people will face longer waits than usual.”

Advanced has not said if the attack has compromised any patient data, or if it is negotiating with the hackers over potentially paying a ransom.

“We want to stress that there is nothing to suggest that our customers are at risk of malware spread and believe that early intervention from our Incident Response Team contained this issue to a small number of servers,” its statement added.

“Since our Health and Care systems were isolated at the end of last week, no further issues have been detected and our security monitoring continues to confirm that the incident is contained, allowing our recovery activities to move forward.”

Commenting on the NHS ransomware attack, CISO at SafeBreach Avishai Avivi said: “This recent attack is yet another example of the evolving adversarial strategy. Rather than directly attacking an organisation, in this case, the NHS, they are targeting the organisation’s supply chain.

“In reading the details available online, my concern is that this attack might have a significantly larger impact than first communicated.”

He added: “Advanced is taking all the correct steps in recovering from the ransomware attack. With that, my concern is that their adjustment recovery time from one week to four weeks indicates an extended ransomware spread, with more systems impacted than originally suspected. While NHS may have taken all the right steps to protect its networks and environments, Advanced was not as rigorous in its efforts.


Recommended


“While there has been no mention of patient data being involved in the attack, the adversaries had access to patient data based on the information available. This is evident in the comments about the ability to update patient care notes and the one-week gap in historical notes.

“This indicates that the database containing the care notes had to be restored, with the restoration leveraging a week-old backup copy.

“At a minimum, the patient care notes have only been accessed by malicious actors to encrypt them. The worst-case scenario is that this data has also been exfiltrated by the attackers and can be used for further ransom.

“This attack, and its resultant impact, are a clear example of why organisations must be sensitive not just to their security posture but also to their supply chain. This is especially important when sensitive PHI is stored in the supply chain vendor.”


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

Michael Behr

Senior Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data