The untold security risk: Medical hijack attacks

News Analysis
Jun 27, 20164 mins

We hear a lot about security exploits in financial services firms and retailers. But a new report shows healthcare organizations are attacked most often.

hack hospital
Credit: Thinkstock

Healthcare is now the most frequently attacked industry, beating out financial services, retail and other industries, according to a new report by TrapX. As a result, healthcare organizations are having trouble keeping pace with the number and sophistication of attacks they have to deal with.

The report, entitled MEDJACK 2, details the sheer scale of attacks that hospitals and other medical establishments suffer on a regular basis. It is a follow-up to a similar report TrapX released last year.

+ Also on Network World: Healthcare needs more IT security pros – stat +

TrapX, a cybersecurity vendor in the deception space, found an increasing number of attacks targeting the healthcare industry and, worryingly, a number of successful attacks that have penetrated security defenses within hospitals.

This is, of course, a huge concern. When a financial institution is breached, people can potentially steal money. But when a hospital is breached, patients’ lives are on the line. Potentially attackers could get access to medical records and prescription systems and tamper with those.

Even more worryingly is that there are now a huge variety of medical devices—from pacemakers to life support systems—that are IP-enabled. The idea of an attacker hacking a medical facility’s network and getting access to a patient’s pacemaker is a worrying concern. And while that has always been simply a case of scary science fiction, TrapX’s research indicates there is much potential there.

The report explains how attackers have evolved and are increasingly targeting medical devices that use legacy operating systems that contain known vulnerabilities. By camouflaging old malware with new techniques, the attackers are able to successfully bypass traditional security mechanisms to gain entry into hospital networks and ultimately access sensitive data.

One factor that should slightly reduce the panic that this report creates is the finding that mainly these attackers are looking for data that they can sell rather than wanting to create real mayhem. There appears to be a lucrative black market for patient data.

Patient data on the black market

Greg Enriquez, CEO of TrapX Security, said persistent medical device attacks targeting hospital networks went undetected for months.

“Over the last year, we saw the compromise of healthcare networks come into the public spotlight, making frequent news headlines,” he said. “Evidence confirms that sophisticated attackers are going after healthcare institutions, and they are highly motivated to gain access to valuable patient records that can net them high dollars on the black market.”

MEDJACK 2 shows that MEDJACK 1 was not an anomaly, but the beginning of a growing trend—a trend that’s become prevalent, Enriquez said. Increasingly attackers use sophisticated attack strategies to steal patient data while remaining undetected, he said.

Combatting attacks

The findings provide a nice segue into a bit of business development for TrapX, whose co-founder, Moshe Ben Simon, displays impressive chutzpah when his number one suggestion to combat these attacks is for hospitals to review budgets and bring in new technologies. He says hospitals need tools that can “identify attacks within their networks, not just at the perimeter.”

TrapX says its solutions detect, analyze and defend against real-time cyber attacks. Rather than trying to simply block attacks, TrapX deceives would-be attackers with turnkey decoys (traps) that “imitate” customers’ true assets. Hundreds or thousands of traps can be deployed, creating a virtual minefield for cyber attacks, alerting customers to any malicious activity with actionable intelligence immediately.

Like many vendors in the cyber security field, TrapX spends a bunch of time looking at what happens out in the real world—both to inform its own product development, but also to educate the public about the risks in different sectors. The company produces a series of reports that demonstrate the results of TrapX research into critical infosec issues, hence the latest reporting zeroing into the medical field.

Commercial imperatives notwithstanding, this report is a sobering document that should make hospital administrators and IT personnel sit up and think about the attack risks within their organization.

benkepes

Ben Kepes is a technology evangelist, an investor, a commentator and a business adviser. His business interests include a diverse range of industries from manufacturing to property to technology. As a technology commentator he has a broad presence both in the traditional media and extensively online. Ben covers the convergence of technology, mobile, ubiquity and agility, all enabled by the cloud. His areas of interest extend to aviation technology, enterprise software, software integration, financial/accounting software, platforms and infrastructure as well as articulating technology simply for everyday users.

He is a globally recognized subject matter expert with an extensive following across multiple channels. His commentary has been published on Forbes, ReadWriteWeb, GigaOm, The Guardian and a wide variety of publications – both print and online. Often included in lists of the most influential technology thinkers globally, Ben is also an active member of the Clouderati, a global group of cloud thought leaders and is in demand as a speaker at conferences and events all around the world.

As organizations react to the demands for more flexible working environments, the impacts of the economic downturn and the existence of multiple form-factor devices and ubiquitous connectivity, Cloud computing stands alone as the technology paradigm that enables the convergence of those trends -- Ben’s insight into these factors has helped organizations large and small, buy-side and sell-side, to navigate a challenging path from the old paradigm to the new one.

Ben is passionate about technology as an enabler and enjoys exploring that theme in various settings.

The opinions expressed in this blog are those of Ben Kepes and do not necessarily represent those of IDG Communications, Inc., its parent, subsidiary or affiliated companies.

More from this author