Papa News
    No Result
    View All Result
    No Result
    View All Result
    Papa News
    No Result
    View All Result

    Infamous crime group takes credit for cyberattack against hospitals

    kitsiosgeo by kitsiosgeo
    November 3, 2023
    in Canada
    0
    Infamous crime group takes credit for cyberattack against hospitals

    [ad_1]

    Breadcrumb Trail Links

    Local News

    Published Nov 02, 2023  •  5 minute read

    Cyber crime illustration
    Illustration of a hacker using a laptop. Photo by scyther5 /Getty Images/iStockphoto

    Article content

    A notorious organized cybercrime gang called Daixin Team has claimed responsibility for stealing millions of records from five southern Ontario hospitals and leaking it online after officials would not submit to ransom demands.

    The organization claims to possess large amounts of data it stole from hospitals in Leamington, Windsor, Sarnia, and Chatham-Kent.

    Advertisement 2

    This advertisement has not loaded yet, but your article continues below.

    Windsor Star

    THIS CONTENT IS RESERVED FOR SUBSCRIBERS ONLY

    Subscribe now to read the latest news in your city and across Canada.

    Unlimited online access to articles from across Canada with one account.Get exclusive access to the Windsor Star ePaper, an electronic replica of the print edition that you can share, download and comment on.Enjoy insights and behind-the-scenes analysis from our award-winning journalists.Support local journalists and the next generation of journalists.Daily puzzles including the New York Times Crossword.

    SUBSCRIBE TO UNLOCK MORE ARTICLES

    Subscribe now to read the latest news in your city and across Canada.

    Unlimited online access to articles from across Canada with one account.Get exclusive access to the Windsor Star ePaper, an electronic replica of the print edition that you can share, download and comment on.Enjoy insights and behind-the-scenes analysis from our award-winning journalists.Support local journalists and the next generation of journalists.Daily puzzles including the New York Times Crossword.

    REGISTER TO UNLOCK MORE ARTICLES

    Create an account or sign in to continue with your reading experience.

    Access articles from across Canada with one account.Share your thoughts and join the conversation in the comments.Enjoy additional articles per month.Get email updates from your favourite authors.

    Article content

    Article content

    The Windsor Star has obtained a purported link to the leaked information, which is posted on the dark web. The link indicates that users can obtain personal information related to patients of the five hospitals.

    The hospitals confirmed Thursday that data from the cyberattack was published, though they did not confirm the perpetrators were with Daixin Team, which reportedly has links to China.

    But Windsor Regional Hospital CEO David Musyj said the blackmailers are part of well-organized operation.

    “The cyberattack is not one person in their basement on a computer,” he said Thursday during a hospital board meeting. “The perpetrators are a sophisticated web of people who extort the healthcare sector. They target us while we are caring for our most critically ill. They attack hospitals while we are emerging from a worldwide pandemic. We are not the first healthcare system to be struck by these bandits and will not be the last.”

    Sarnia’s Bluewater Health, Chatham-Kent Health Alliance, the Windsor-Essex hospice, Erie Shores HealthCare, Hôtel-Dieu Grace Healthcare, and Windsor Regional Hospital are still locked out of some of their systems following the Oct. 23 cyberattack. Even the hospital websites were still down on Thursday.

    Advertisement 3

    This advertisement has not loaded yet, but your article continues below.

    Article content

    Along with shutting down digital and technology-based systems at the hospitals, the blackmailers also stole large amounts of personal information about staff and patients. When the hospitals would not bend to ransom demands, the criminals started posting stolen data online.

    Local police departments, the Ontario Provincial Police, the FBI, and INTERPOL are all involved in the criminal probe.

    Daixin has previously taken credit for many other similar cyberattacks against organizations including a German water metering company, low cost airline AirAsia, Missouri’s Fitzbiggon Hospital, and OakBend Medical Centre in Texas.

    “Daixin has been operating since the middle of last year, and has previously targeted multiple other organizations in the healthcare sector,” said Brett Callow, a threat analyst with the international cybersecurity firm Emsisoft Ltd. “The individuals behind it were likely previously involved with other ransomware operations, and still may be. This is not the first time hospitals have been targeted and, unfortunately, it will not be the last. It’s not a matter of if another hospital will be hit, it’s a matter of when.”

    Advertisement 4

    This advertisement has not loaded yet, but your article continues below.

    Article content

    After infiltrating the hospitals’ technology systems, hackers blocked their access to Wi-Fi, email, and patient information systems, causing upheaval and stress for thousands of patients across southwestern Ontario.

    The attackers locked the hospitals out of their own systems by targeting TransForm Shared Service Organization, which runs technology systems for all five facilities.

    Musyj said the hospitals still don’t know how much data was taken. But he added that an investigation is underway and they hope to have more information on that soon.

    “The bad actors have published some of the data they stole,” he said. “They did this because we would not succumb to their ransom demands. We closely examined whether to pay, but we knew, and our experts and law enforcement, all confirmed, that we cannot trust the promise of criminals to delete this information. We learned that payment would not speed up the safe restoration of our network, and so we did not pay.”

    Musyj said that decision falls in line with a joint statement issued Wednesday by the 50 members of the International Counter Ransomware Initiative, including Canada, that have pledged never to pay ransom to cybercriminals.

    Advertisement 5

    This advertisement has not loaded yet, but your article continues below.

    Article content

    Despite that pledge, Callow said governments around the globe have failed to do enough to stop cybercriminals.

    “Governments have failed to get a handle on ransomware and the situation is now as bad as it’s ever been, perhaps worse,” he said. “We desperately need new strategies to counter the problem as the current ones very clearly are not working. I believe the time has come for governments to seriously consider banning ransom payments or, at least, imposing significant restrictions on the circumstances in which they can be paid. The attackers are financially motivated, and less money would mean less attacks.”

    Given their willingness to shut down vital hospital systems and expose patient data, Callow said the hackers have the ability to devastate the healthcare system.

    “The most concerning aspect of these incidents is the potential for patient care to suffer, perhaps with fatal consequences,” he said. “If doctors are without access to critical systems and patient information, it’s likely that the quality of care will suffer. And not necessarily only at the affected hospitals. Nearby hospitals may also be impacted, as they may need to take on additional patients at a time when their resources are already stretched very thin.”

    Advertisement 6

    This advertisement has not loaded yet, but your article continues below.

    Article content

    The U.S. government’s Cybersecurity and Infrastructure Security Agency issued an advisory about Daixin Team last year.

    The agency said Daixin is a cybercrime group that is actively targeting businesses, predominantly in the Healthcare and Public Health (HPH) sector, with ransomware and data extortion operations.

    The U.S. agency said Daixin works by deploying ransomware to encrypt servers responsible for healthcare, including electronic records, diagnostics services, imaging services, and intranet services.

    The gang has also “exfiltrated” personal identifiable information and patient health information, and threatened to release the information if a ransom is not paid, the agency said.

    “The Daixin Team is a ransomware and data extortion group that has targeted the HPH Sector with ransomware and data extortion operations since at least June 2022,” the agency said. “Since then, Daixin Team cybercrime actors have caused ransomware incidents at multiple HPH (Healthcare and Public Health) Sector organizations.”

    Callow said hackers in these cases often upload the stolen information to a URL that is difficult to download due to its size, so that might limit the number of people who can access it.

    “Hopefully the actual impact to individuals may not be too bad,” he said. “That said, hope for the best and plan for the worst. You should assume that information may be misused by cyber criminals, so strategize accordingly.”

     — with files from Madeline Mazak

    twilhelm@postmedia.com

    twitter.com/WinStarWilhelm

    Article content

    Share this article in your social network

    Comments

    Postmedia is committed to maintaining a lively but civil forum for discussion and encourage all readers to share their views on our articles. Comments may take up to an hour for moderation before appearing on the site. We ask you to keep your comments relevant and respectful. We have enabled email notifications—you will now receive an email if you receive a reply to your comment, there is an update to a comment thread you follow or if a user you follow comments. Visit our Community Guidelines for more information and details on how to adjust your email settings.



    [ad_2]

    Source link

    Tags: CreditCrimecyberattackGrouphospitalsInfamoustakes
    Previous Post

    FTX founder Sam-Bankman-Fried convicted of defrauding cryptocurrency customers | CBC News

    Next Post

    Deep divisions lurk behind Israel’s united wartime front

    Next Post
    Deep divisions lurk behind Israel’s united wartime front

    Deep divisions lurk behind Israel's united wartime front

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    CATEGORIES

    • Africa
    • Asia Pacific
    • Australia
    • Business
    • Canada
    • Cryptocurrency
    • Economy
    • Entertainment
    • Europe
    • Gossips
    • Health
    • India
    • Lifestyle
    • Middle East
    • New Zealand
    • Politics
    • Sports
    • Technology
    • Travel
    • UK
    • USA

    LATEST UPDATES

    • How To Apply For A Visa For Armenia
    • Starmer pushed on EU youth mobility as Tory leadership rivals make final pitch – live
    • Aamir Khan offers condolences after ex-wife Reena Dutta’s father passes away

        © 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

        No Result
        View All Result

            © 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.