pwshub.com

Healthcare attacks spread beyond US, just ask Star Health

Leading Indian health insurance provider Star Health has admitted to being the victim of a cyber attack after criminals claimed they had posted records of 30-milion-plus clients online.

When news of a potential break appeared in September, the firm asserted that initial assessments showed "no widespread compromises" and that "sensitive customer data remains secure."

At the time, a hacker who goes by "xenZen" was allegedly using two Telegram chatbots to leak the data. One chatbot offered PDFs of claim documents, another allowed users to request up to 20 samples of over 31 million records containing sensitive information like body mass index. The perp also claimed to have the images of Star Health customers' national identity card.

Star Health this week told The Register that it acknowledges "unauthorized and illegal access to certain data" but added "operations remain unaffected."

"A thorough and rigorous forensic investigation, led by independent cyber security experts, is underway, and we are working closely with government and regulatory authorities at every stage of this investigation, including by duly reporting the incident to the insurance and cyber security regulatory authorities apart from filing a criminal complaint," explained the care provider.

Star Health has also approached the Madras High Court, which ordered all relevant parties to disable any access to the information.

Star Health said its CISO was cooperating with the investigation and had not been found guilty of any wrongdoing, adding "We request that his privacy be respected as we know that the threat actor is trying to create panic."

xenZen has claimed that they obtained the records directly from Star Health's CISO.

"Star Health management CISO [name redacted] (as mc6) sold all this data to me and then attempted to change deal terms saying senior management of company needs more money for backdoor access," posted xenZen, along with screenshots of the alleged conversations.

Once operating on Telegram, the threat actor has since shifted toward self-hosting. The Reg has viewed, but chosen not to link to, the hacker's website where the stolen data now sells for $150k and chunks of 100k entries can be had for $10k.

Star Health has filed suit against Telegram, Cloudflare and xenZen (which is listed as having an unknown address) among others, for their roles in enabling the leak. Court documents dated September 24 show the insurer seeking a permanent injunction to prevent the defendants from publishing or sharing the stolen data and using its trade names, logo, and website domain. The court granted an interim injunction on the same day.

The suit also included requests for the removal of Telegram bots and websites involved in the leak, and for the disclosure of user information tied to the breaches.

Healthcare organizations and hospitals have recently been the target of ransomware and other cyber threats. This month, an Alabama hospital informed 61,000 patients their personal data was accessed one year prior. And at the end of September, The University Medical Center in Lubbock, Texas, was forced to severely limit operations following a hit by ransomware operators. And last week, cybergang Trinity allegedly infected Rocky Mountain Gastroenterology – a Colorado-based clinic, with ransomware. ®

Source: theregister.com

Related stories
1 week ago - Only level-one trauma unit in 400 miles crippled Ransomware scumbags have caused a vital hospital to turn away ambulances after infecting its computer systems with malware.…
1 month ago - Ransomware attacks continue to plague global industries, with Unit 42's recent analysis revealing a troubling rise in activity. During the first six months of 2024, Unit 42, the threat intelligence team of Palo Alto Networks, monitored...
1 day ago - As if hospitals and clinics didn't have enough to worry about At least one US healthcare provider has been infected by Trinity, an emerging cybercrime gang with eponymous ransomware that uses double extortion and other "sophisticated"...
1 month ago - Whether attack slowdown continues downward trend is the million dollar question that security researchers can't answer Critical industrial organizations continued to be hammered by ransomware skids in July, while experts suggest the perps...
1 week ago - Ransomware criminals believed to have taken orders from intel services The relationship between infamous cybercrime outfit Evil Corp and the Russian state is thought to be extraordinarily close, so close that intelligence officials...
Other stories
17 minutes ago - If you're looking to get set up with ACA health coverage, the time is nearly upon you.
17 minutes ago - Here's today's NYT Mini Crossword answer. These answers will help you solve New York Times' popular crossword game, Mini Crossword, every day!
35 minutes ago - It worked – alleged pump and dump schemers arrested in UK, US and Portugal this week The FBI created its own cryptocurrency so it could watch suspected fraudsters use it – an idea that worked so well it produced arrests in three countries.…
41 minutes ago - Tesla CEO Elon Musk says his company’s robotaxi will “probably” be in production before 2027 — and predicts it will cost less than $30,000.
1 hour ago - Tesla's Elon Musk shows latest Tesla Optimus Robot dancing and tending bar at the 'We, Robot' event.