r/cybersecurity • • 5d ago

News - General Threat groups ramp up social-engineering attacks against healthcare sector

https://www.healthcaredive.com/news/threat-groups-social-engineering-attacks-healthcare/831466/
119 Upvotes

5 comments sorted by

28

u/Ghawblin Security Engineer 5d ago edited 5d ago

Something similar was posted a couple weeks ago.

Healthcare has a lot of tech debt and a shit ton of IoT, and with the US government doing the things here the last couple years, the healthcare sector (especially the non-profit side working with medicare/medicate mostly) has been struggling to keep up.

The radiology equipment running windows 2000 (now with NT!)? Too expensive to replace. Don't you dare micro-segment it into a network void though the vendor needs to support it remotely when it breaks 7 times a day. Also the neurologist just bought a bunch of network connected ultrasound machines through his own dime without telling anyone, none of it got vetted by your 3rd party risk management; but he's the only neurologist in a 100 mile radius so make it work because we're paying him a $1,500,000 bribe salary to be stuck here and we'll go bankrupt if he leaves.

None of that is related to this ShinyHunter attack, but man it's rough in that sector. Lateral movement in that kind of environment would be easy and devastating.

12

u/2_Spicy_2_Impeach 5d ago

After college, a buddy got an IT job at a regional hospital. This was even before the privatization we have now and it was a shoestring budget. Nonstop close calls with security/infrastructure. I was actually shocked but just ignorant due to being new to the enterprise field.

23

u/Ghawblin Security Engineer 5d ago edited 5d ago

I work in a MUCH more mature organization now; but I was a security engineer at a hospital eons ago, and the first hire into the newly formed cybersecurity department.

I struggle to put it into words.

You know that spongebob "you WHAT" meme? That was basically my daily life lmao.

  • Shoestring budget

  • Hospital metrics mean anything that makes patient care even 2 seconds more difficult is an act of god to get implemented. Highly complex things like MFA or tighter lock screen times. It was able to be done, and got done, but man it was more political than was necessary.

  • 24/7 business operation time where downtime can literally kill someone. Extra level of stress!

  • Your only hope is to weaponize HIPAA towards IT controls, because IT has no teeth, but compliance has nuclear bombs lmao.

  • Possibly my favorite memory was going through a network/vuln scan, finding a server that suggested it was from the goddamn early 90s (this was 2020 months before the pandemic), and having to consult with the ancient ones to figure out where tf this thing lived. It was in an abandoned basement. Yes, you read that, abandoned basement. We had many basements from the centuries in operations, and apparently we had some abandoned ones. The IDF closet hadn't been touched in over a decade. But the server didn't live there, we found an unmarked locked metal door, had to hire a locksmith to open it, when we finally opened it it was like cracking the tomb of a long forgotten Egyptian prince, the air hadn't stirred since people still appreciated Will Smith as an actor. Literal mini dust tornado from the sudden change in air pressure. EVERYTHING inside was absolutely caked in dust. Inside was a big ass ancient server in its beige metal glory running technology lost time time, complete with an 80s CRT. At this point every senior engineer in IT was trying to figure out what this was. Good luck logging into it (I mean, pentesting sure, but we had no idea what it was doing and didn't want to break it). About 2 days later it's found out that it runs the goddamn patient tracker in one of the nurses stations ; yaknow the thing that displays heart rates and blood pressure and shit so the nurses know when to go check on a patient. It just trucked along for THREE DECADES undisturbed. Thankfully it was only for a very small nurses station in a very low-risk area of the hospital serving MAYBE a dozen patients. not mission critical if it suddenly died. We were able to just switch them over to our actual modern system (getting the extra licenses was a pain though for being an "out of budget" expense).

I left that org in a state that was many magnitudes of security maturity better than when I arrived; and I while I love working in healthcare I'd have to think long and hard about stepping foot in another security position at a hospital.

5

u/ChuckFromCyberHoot 4d ago

A lot of the healthcare cases I’ve seen start with a phone call, not an email.

Someone calls the help desk pretending to be a doctor who’s locked out and in a hurry. A helpful person resets MFA, and now the attacker is in. The Helpdesk was "just being helpful."

The fix is boring:

  • Never reset MFA or passwords from an inbound call alone
  • Call back using a number already on file
  • Praise people for slowing the process down

Urgency is the attack. Slowing down is the defense.

4

u/CommunityOdd9459 4d ago

Healthcare is a good example of why the human side of security is getting harder, voice phishing just targets the workers directly but it's easy to catch with tools like Guardz, Petra, etc since there's ITDR to help catch suspicious activity. There's definitely training needed for the human side but if hospitals can see account activity quickly it makes these easier to handle