Showing posts with label health sector. Show all posts
Showing posts with label health sector. Show all posts

Wednesday, April 2, 2025

Legacy Medical Devices Remain Easy Targets for Cyber Threats

 

Do you think that your health data secure?


Most of the people don't really think about this question. But imagine, what would you do if your health data ended up on the internet one day? Once it's exposed, you can't undo it. That's scary and disturbing, isn't it?


Anyone who worked with medical systems knows that it is quite difficult to patch the vulnerabilities on these systems. Main reasons are: 1) Many of the systems run on outdated software that no longer supports new patches. 2) Updates are too risky because they can interrupt care or cause devices to fail during use. So, many of these devices stay unpatched and highly vulnerable to cyber attacks.


Researchers from Claroty's Team82 analyzed over 2.25 million Internet of Medical Things (IoMT) devices and more than 647,000 operational technology (OT) devices across 351 healthcare organizations. They found that 99% of these organizations had vulnerabilities with publicly available exploits, as listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. (Yes, 99%. We can say (almost) "all of them")


You can find the report in the following link:

https://bit.ly/4j1es7d


https://bit.ly/3FOYOgp


Headlines:

"...the firm was able to analyze the security state of more than 2.25 million IoMT devices and more than 647,000 OT devices across 351 healthcare organizations – and found that 99% of the organizations are vulnerable to publicly available exploits..."


Tuesday, April 23, 2024

Change Healthcare’s Ransomware Attack

Let's repeat the painful truth once more: Lack of cybersecurity countermeasures can cost you much more than you expected.

The cyber attacks (especially ransomware attacks) on the health sector have been increasing in recent years. Health sector players have to take this fact into consideration in order to avoid being the next cyber victim of the cyber crime market.


UnitedHealth states that the total costs of the February cyber attack for the first quarter of 2024 stands at $872 million. The total cost reached "$1 billion" with the remediation costs, including a $22 million payment to the ALPHV/BlackCat-affiliated ransomware group. (If you hire 20 cyber security experts each for $250,000, it will cost you $5 million per year.)


This attack also had effects on their shares. ($0.74 per share.)


https://bit.ly/3wcOdHF


"It's a charge that eclipsed that of casino group MGM, which didn't pay a ransom following an attack on its systems last year, and which faces recovery costs of $100 million to rebuild its systems and paying for the fallout from outages, operational disruptions, allegedly leaked data and more."


"The company warned that, financially, the total cost of the cyberattack is estimated to be between $1.35 billion and $1.6 billion for calendar year 2024."