FBI, HHS & CISA Warn of Ryuk Ransomware Healthcare Attacks

The FBI, HHS, and the Cybersecurity and Infrastructure Security Agency (CISA) have revealed that there is “credible information” that cybercriminals will be launching attacks on healthcare providers in the coming weeks and months. According to the warning, all healthcare providers with access to Patient Health Information must do what they can to recognize, deter, and report these attacks as they happen. Based on the release, it is clear that certain tactics and targets will be more popular than others. Officials have determined that the hackers will attempt to “infect systems with Ryuk ransomware for financial gain.” These malicious individuals will also use Trickbot malware to disrupt services, steal data, and utilize ransomware for extortion. This is part of an escalating pattern of ransomware attacks targeting healthcare organizations that shows no signs of slowing down.
trickbot malware diagram showing how it infiltrates healthcare systems and deploys ryuk ransomware
The specific threats “include credential harvesting, mail exfiltration, cryptomining, point-of-sale data exfiltration, and the deployment of ransomware, such as Ryuk.” The officials believe that the scale of the assault will be unlike anything witnessed before. These attacks are years in the making, as Trickbot’s developers have worked to improve the malware to be less detectable and harder to root out once implanted. It is also believed that the current healthcare system is overburdened due to the pandemic, making it a more vulnerable target. While the current actions of the cyber attackers appear to be in preparation for infiltrating high-profile targets, it’s important for every healthcare provider to prepare — including smaller medical practices and doctor’s offices. Although it is difficult to thoroughly prepare for every eventuality, some actions can provide heightened protection to deter hackers or limit their access. The following steps are something every medical provider should take:
  • Keep an eye out for manufacturer releases for operating systems, firmware, and software and implement them as soon as possible.
  • Integrate multifactor authentication as much as you can.
  • Insist on password changes often, and do not allow people to reuse their passwords.
  • Disable unnecessary Remote Desktop Protocols.
  • Implement the 3-2-1 Rule for data backups: three copies of all critical data retained on at least two different types of media, with at least one stored offline.
The advisory also noted that organizations that are victims of ransomware may not regain access to their devices or have data returned after paying. In fact, the decryption keys “sold” to the victim may not work — and paying might make the organization more likely to be attacked again. Preparing for such a threat is not something that every doctor’s office is capable of doing on their own. In times like these, it is necessary to secure data by any means necessary, even if that requires bringing in a third party for help. A qualified managed security partner can evaluate a medical practice to determine its specific risks. From there, they can provide general vulnerability protection while implementing the recommendations issued by the FBI, HHS, and CISA. WheelHouse IT’s Managed Detection and Response service is specifically designed for this kind of proactive, around-the-clock threat hunting. Now is the time to act and shore up the protections around medical data. This threat is real and specific — a few major actions on the part of responsible stakeholders can prevent a massive loss of data or money. Contact WheelHouse IT today to get started.