On July 26, a malware attack on AnMed caused doctor’s offices to be shuttered, surgeries to be rescheduled, and patients to be left largely in the dark about what (or who) caused the disruption.
Nearly a month after the initial attack was launched, AnMed confirmed the hack was the work of "cybercriminals" who accessed the system's data, though specifics on what — and whose — data was stolen has not been revealed.
"It was an attack that was orchestrated by a group of individuals motivated by financial gain, with complete disregard for the important role AnMed plays in this community and the overall health of our community," AnMed CEO William Kenley said in an Aug. 21 video statement. "Make no mistake, it was an attack on all of us."
AnMed is working with cybersecurity consultants to further investigate the data breach, and warned patients and employees to be wary of any "suspicious communications." Kenley said a "detailed review" of the system's data is ongoing, and more information will be released to the public after it's verified. "AnMed has been in this community for more than 100 years," Kenley said. "We've been through challenging times. This is not the first."
It took until Aug. 11 for AnMed to restore full access to patients’ electronic health records, according to the health care system.
The health care system said local, state, and federal authorities are investigating the incident, and urged patients to be cautious of any communications asking for payments from AnMed. The system asks patients to call a customer care line, and to be patient as operations might be delayed by the ongoing disruption.
The malware attack on AnMed represents a much larger problem with lax data security and investment in the U.S., according to Floyd Harper, a cybersecurity veteran who has worked in the field since the early 1980s, helping to prosecute at least 1,000 cybercriminals.
Harper’s latest venture is aimed at addressing the decades-long incompetencies in cybersecurity infrastructure online, which was unraveled at the dawn of the “sharing internet” in the 1990s. For 20 years, the West Columbia businessman hoped “that one day the world would get serious about cybercrime,” but he’s yet to see businesses and government agencies make the necessary investments to protect data and train employees on best practices.
“Since 1993, convenience has been more important than protecting your data,” Harper notes in documentation from his new venture XPRESS Group, which aims to deliver a highly sophisticated product within a year.
The result of favoring convenience is costly. According to the U.S. Small Business Administration, cyberattacks cost the economy about $445 billion a year.
And the impact goes beyond financial. A cyberattack that breaches client information leads to a lack of trust.
“Sixty percent of all small businesses fail within six months after a cyberattack,” said Harper, who’s consulted with the federal government, as well as major corporations like VISA, on cybersecurity.
South Carolina-based experts said there is no way to prevent a cyberattack attempt — one Charleston-based researcher said a user is targeted within seconds of going on the internet — there are ways to protect data and prevent catastrophic disruptions to business operations.
“There's no way to stop these attacks that I know of … but there are a lot of things they can do to protect themselves,” Harper said.
What is malware, and what does it target?
Malware — the umbrella term for cyberattack types like ransomware and viruses — are increasingly common, especially as easy-to-obtain software and AI make these types of attacks less technical, according to Ross Clarke, a Charleston-based cybersecurity expert who works with Harper.
“The dangerous part of this is that proliferation of that ability (to cyberattack) without the knowledge has led to a lot of catastrophic attacks,” said Clarke, a researcher who started participating in hackathons as a teenager and co-founded cybersecurity firm CAMA Security.
Clarke explained there are different types of cybercriminals:
● Hacktivists, who release stolen data publicly for “good”
● A professional site hacker with a nation-state sponsor, whose aim is to either steal state secrets or create sociopolitical disruptions
● The casual hacker who simply wants to see with what they can get away with
● And the profit-driven hackers whose sole aim is monetary gain
“They have the skills of the professional hackers,” Clarke said of profit-driven groups. “They aren't aligned with any nation-state directly. They're making money off of ransom. They will get into a network, they will steal all of the data, exfiltrate it, and then wipe all of the data off that network so that company can't run, and then demand a ransom. Just like a pirate of old.”
Hackers with connections to intelligence communities are also common, according to Richard Brooks, a Clemson professor who studies mathematics and computing. While disrupting critical infrastructure — like recent hacks on Minnesota’s water systems — can be the motive, smaller businesses or even nonprofits with little to no security can also be held up for ransom. Brooks advised victims never to pay a ransom.
“Why would you trust these people?” the professor posited. “You're encouraging people to do more with it. It’s hard, but I personally would just start over from scratch.”
There has been little information distributed about what the team behind the AnMed attack want, but Harper and Clarke believe the scale and efficiency of the malware point to a highly sophisticated hacking group.
The No. 1 way hackers get into systems? Human error.
Whether it’s buying employee credentials, stealing their information by way of a phishing scam, or creating a fake employee profile they embed within the system, hackers often slip in quietly and wait before launching their attack, Clarke explained.
“I've yet to see a single successful ransomware attack where the hackers were not already embedded for at least a month, if not a year-plus,” he said.
Clarke said 70 percent of cyberattacks stem from an employee opening the door, most of the time unintentionally. Sophisticated phishing scams, including malware embedded into an attached PDF file, are common ways employees’ credentials get stolen and used to initiate an attack.
And these days, phishing scams are becoming highly sophisticated.
Brooks, the Clemson professor, said he’s received several emails allegedly from high-level university administrators that have turned out to be phishing scams. He didn’t realize it until the university’s IT department notified him. He spoke of another company that fell victim to a cyberattack after a phishing scam sent out an email with a malware-infected PDF attached. It was labelled as the next year’s benefits package.
“If you're working for any company, you get emails with PDFs saying this is the new benefits package. There's no reason why you should suspect that,” Brooks said.
Rebuilding the system
According to Clarke, a user is targeted for a cyberattack within 24 seconds of going on the internet.
“And within that first 30 seconds, a crafted exploit is already being tested against you,” he said.
Since the early 2000s, the cybersecurity industry has been focused on physical breaches to servers, but an equal risk exists on the internet and in cloud-based software systems. The internet’s ease with which users can set up accounts, save passwords, and share their data has led to a false sense of security. Harper said it will take a complete overhaul of infrastructure and user psychology to make technology truly safe again.
Harper said a lack of trained IT specialists, an unwillingness for business owners to invest in capable cybersecurity systems, and a below-average status quo set by the federal government have all contributed to a vulnerable system.
Even if a business takes steps to protect their systems, a vendor might not do the same, Harper explained, referencing how a data management program a hospital system uses might get hacked, offering a way into medical records and systems.
“Everybody’s targeted,” he said.
Vigilance is the key, he added. “Assume every email, every location, every website is from a hacker that is trying to steal your data, money, and more.”
Comments
No comments on this item Please log in to comment by clicking here