Beware, health care providers — there’s a new form of cyberattack coming to an organization near you! Disruptionware is an “emerging category of malware designed to suspend operations within a victim organization by compromising the availability, integrity and confidentiality of the systems, networks and data belonging to the target.”1 Far more destructive than “garden-variety” malware and ransomware attacks, disruptionware attempts to encrypt and deny users access to their data, working as a “layered attack” designed to “disrupt operations and production in [target] environments (as well as infrastructure) in order to achieve some other strategic goal.”2
Additional forms of evolving ransomware attacks — designed to block access to the victim’s computer systems until money is paid — are an increasingly prevalent threat to health care organizations. According to the FBI, hospitals and health care institutions are the primary targets of these high-impact ransomware attacks because of the critical role they play in providing lifesaving services, and the fact that health care institutions usually do not have the time to restore backups to get their networks working again and running safely and securely after an attack.3
The United Kingdom’s Department of Health and Social Care has estimated that the highly publicized 2017 global WannaCry cyberattack that affected its National Health Service (NHS) cost the NHS £92 million ($120.4 million) in lost patient care and IT support provided to its organization.4 Approximately 19,000 patient appointments were cancelled as a result of the attack.5
Ransomware has been so destructive that the FBI recently issued a Public Service Announcement (PSA) warning about “high-impact” attacks on critical private- and public-sector institutions.6 According to Emsisoft, a cybersecurity firm, since the beginning of 2019 there have been at least 621 reported successful ransomware attacks against U.S.-based corporations. Of these, at least 491 (almost 80%) were targeted against health care providers. Another 68 (11%) were directed at county and municipal institutions, and 62 (10%) were focused on school districts. Cybersecurity Ventures has predicted that ransomware payments alone by victim companies will have exceeded $11.5 billion in 2019 — representing an increase of almost 30% over the approximately $8 billion paid in 2018.7
Hackers are increasingly using new and diverse techniques to launch multiple forms of cyberattacks, including new Remote Desktop Protocol (RDP) attacks, and leveraging various software vulnerabilities to infect organizations through backdoor channels. RDP attacks are becoming far more common because of the simplicity of many users’ login credentials and the problems with “credential stuffing” attacks, while companies are not doing enough to “whitelist” exclusively acceptable computer software and applications to prevent security holes caused by numerous software vulnerabilities in unsecured and sometimes untested software applications. Best practices to avoid such attacks include: (1) hardening your IT systems using either ISO or NIST cybersecurity frameworks and (2) ensuring that you train your employees on cyber social awareness defense techniques.
The FBI’s PSA serves as a warning to businesses that they should have a plan in place to respond efficiently and appropriately in the event of high-impact ransomware and disruptionware attacks. Such plans should include, among other things, clear designation of responsible individuals (inside and outside the company), procedures for contacting law enforcement, and a firm understanding of what the company’s data is as well as a good understanding of its importance in the overall business plan.
Finally, businesses need a current and workable Incident Response Plan and/or Disaster Recovery Plan for getting the organization up and running again as quickly as possible if there is a cyberattack. Businesses would be wise to review how their systems are backed up, as reliable and readily accessible backups are often critical in resuming normal business operations as quickly as possible.