Papa News
    No Result
    View All Result
    No Result
    View All Result
    Papa News
    No Result
    View All Result

    Hackers wanted multimillion dollar ransom to end hospital attack

    kitsiosgeo by kitsiosgeo
    November 16, 2023
    in Canada
    0
    Hackers wanted multimillion dollar ransom to end hospital attack

    [ad_1]

    Breadcrumb Trail Links

    Local News

    Published Nov 16, 2023  •  Last updated 3 hours ago  •  3 minute read

    cyber
    Getty Images. Cyber attack stock photo. Peter J. Thompson/National Post  Photo by Getty Images /jpg

    Article content

    The hackers who shut down systems at five southwestern Ontario hospitals offered to cease the attack — and keep stolen staff and patient information off the dark web — for a ransom payment of about $8 million.

    A source with knowledge of the situation confirmed to the Star that the ransom demand, in U.S. dollars, was in the “high seven digits.”

    Article content

    Even after the hackers started posting millions of patient files online, the hospitals and their shared service provider refused to pay the ransom.

    Advertisement 2

    This advertisement has not loaded yet, but your article continues below.

    Windsor Star

    THIS CONTENT IS RESERVED FOR SUBSCRIBERS ONLY

    Subscribe now to read the latest news in your city and across Canada.

    Unlimited online access to articles from across Canada with one account.Get exclusive access to the Windsor Star ePaper, an electronic replica of the print edition that you can share, download and comment on.Enjoy insights and behind-the-scenes analysis from our award-winning journalists.Support local journalists and the next generation of journalists.Daily puzzles including the New York Times Crossword.

    SUBSCRIBE TO UNLOCK MORE ARTICLES

    Subscribe now to read the latest news in your city and across Canada.

    Unlimited online access to articles from across Canada with one account.Get exclusive access to the Windsor Star ePaper, an electronic replica of the print edition that you can share, download and comment on.Enjoy insights and behind-the-scenes analysis from our award-winning journalists.Support local journalists and the next generation of journalists.Daily puzzles including the New York Times Crossword.

    REGISTER TO UNLOCK MORE ARTICLES

    Create an account or sign in to continue with your reading experience.

    Access articles from across Canada with one account.Share your thoughts and join the conversation in the comments.Enjoy additional articles per month.Get email updates from your favourite authors.

    Article content

    Cybersecurity experts say that was the right decision. Brett Callow, an advisory board member with the Royal United Services Institute’s Ransomware Harms project, said outlawing the payment of ransoms would put a quick end to the attacks in many cases.

    Florida and North Carolina have already banned public sector bodies from paying ransom demands connected to ransomware attacks.

    “These attacks are financially motivated,” said Callow, whose work with the institute includes examining the impact of ransomware on victims. “If they cannot monetize them, there will be no attacks. It doesn’t have to be an all-or-nothing scenario either. Restricting the circumstances in which organizations are permitted to pay could have an impact, too. That could make Canadian organizations less attractive targets.

    “Lots of organizations pay when they don’t absolutely need to.”

    The ransomware attack targeted Bluewater Health, Chatham-Kent Health Alliance, Erie Shores HealthCare, Hôtel-Dieu Grace Healthcare, and Windsor Regional Hospital. The hackers also hit TransForm Shared Service Organization, which runs supply and technology systems for all five hospitals.

    Advertisement 3

    This advertisement has not loaded yet, but your article continues below.

    Article content

    It’s unknown exactly how long the hackers were in the organizations’ systems, but the attack was detected on the morning of Oct. 23.

    The criminals infiltrated the hospitals’ technology systems, then blocked their access to Wi-Fi, email, and patient information systems. Some information from all five hospitals was stolen, but Bluewater Health was the hardest hit.

    The Sarnia hospital has confirmed the hackers stole a database report containing information about every patient of Bluewater Health or its predecessor institutions since February 24, 1992.

    The breach at Bluewater Health alone amounts to about 5.6 million records pertaining to roughly 267,000 people. The hospital said the stolen data included social insurance numbers for about 20,000 patients.

    The hackers have already posted at least four rounds of Bluewater Health data on the dark web, with a promise that more is coming.

    An infamous organized cybercrime gang called Daixin Team, which emerged around the middle of 2022, claimed responsibility for the sustained attack.

    Daixin has previously taken credit for many other similar blackmail attacks against organizations including a German water metering company, low cost airline AirAsia, Missouri’s Fitzbiggon Hospital, and OakBend Medical Centre in Texas.

    Advertisement 4

    This advertisement has not loaded yet, but your article continues below.

    Article content

    Canada has yet to outlaw ransom payments. But it is among the 50 members of the International Counter Ransomware Initiative (CRI) that have pledged to never pay ransom to cybercriminals.

    Callow said the highest known cyberattack ransom demand on record, against a company called MediaMarkt, was $240 million. The company did not pay the ransom.

    The highest ransom demand known to have been paid was $40 million. The victim in that case was a company called CNA Financial.

    Given that, Callow said a ransom demand in the $8 million range would not be unheard of.

    “It varies massively according to the group and the victim, but that certainly wouldn’t be a surprising amount,” said Callow, also a threat analyst with the cybersecurity firm Emsisoft.

    He said the blackmail target and the ransom demand often depend on various factors such as the size of an organization and what it can likely afford, its financial statements, insurance policies, and what criminals can glean from publicly available documents.

    “Some organizations are specifically targeted,” said Callow. “But in most cases, the attack starts off random. They send out emails with malicious links, and whoever clicks is the unlucky next victim.”

    Advertisement 5

    This advertisement has not loaded yet, but your article continues below.

    Article content

    “Or they were scanning the web and came across a vulnerable Internet-facing server that the organization was running. Or they may have come across access to a hospital that was being sold and decided this was a potentially good candidate. There are numerous ways it could have happened.”

    While ransomware attacks are on the rise, Callow said it’s hard to give a definitive number of incidents or confirm if Canadian organizations are more frequently targeted.

    “It’s extremely hard to tell how many incidents there are because companies aren’t inclined to come forward,” said Callow. “This is a problem because if policy makers can’t see how many attacks there are, or whether they’re trending up or down, how do they know whether their policies are working?”

    twilhelm@postmedia.com

    twitter.com/WinStarWilhelm

    Article content

    Share this article in your social network

    Comments

    Postmedia is committed to maintaining a lively but civil forum for discussion and encourage all readers to share their views on our articles. Comments may take up to an hour for moderation before appearing on the site. We ask you to keep your comments relevant and respectful. We have enabled email notifications—you will now receive an email if you receive a reply to your comment, there is an update to a comment thread you follow or if a user you follow comments. Visit our Community Guidelines for more information and details on how to adjust your email settings.



    [ad_2]

    Source link

    Tags: attackdollarHackershospitalMultiMillionransomWanted
    Previous Post

    Sanitarium Weet-Bix Kids TRYathlon returns in March – Times

    Next Post

    How to watch the Cricket World Cup final and what time it’s being shown around Australia

    Next Post
    How to watch the Cricket World Cup final and what time it’s being shown around Australia

    How to watch the Cricket World Cup final and what time it's being shown around Australia

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    CATEGORIES

    • Africa
    • Asia Pacific
    • Australia
    • Business
    • Canada
    • Cryptocurrency
    • Economy
    • Entertainment
    • Europe
    • Gossips
    • Health
    • India
    • Lifestyle
    • Middle East
    • New Zealand
    • Politics
    • Sports
    • Technology
    • Travel
    • UK
    • USA

    LATEST UPDATES

    • How To Apply For A Visa For Armenia
    • Starmer pushed on EU youth mobility as Tory leadership rivals make final pitch – live
    • Aamir Khan offers condolences after ex-wife Reena Dutta’s father passes away

        © 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

        No Result
        View All Result

            © 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.