pwshub.com

ICO plans $7.7 million fine for Advanced over 2022 attack

The UK's data protection watchdog says it plans to fine a managed software provider to the NHS £6.09 million ($7.7 million) for failings that led to a 2022 ransomware attack.

Reading the press release, we've never seen the word "provisionally" appear so many times in such a short bit of copy, but the Information Commissioner's Office's (ICO) really sought to hammer home the fact that nothing is set in stone and the ultimate punishment will be decided after the vendor has had its say on the matter.

That vendor is Advanced Computer Software Group; you may remember it from El Reg stories published almost two years ago to the day. Advanced pulled its systems offline on August 4, 2022, in an incident that was eventually attributed to LockBit, back in its heydey which has thankfully now ended.

NHS non-emergency phone operators on the 111 line were forced to revert to pen-and-paper operations as disruptions continued for weeks. Some systems were still down in October of that year.

There are a number of things that really irked information commissioner John Edwards about this particular case. For one, the incident was allowed to take place, the ICO said, because a customer account without multi-factor authentication (MFA) was used to breach the vendor's systems.

We know specifically, though, that legitimate credentials were used to create a remote desktop session to Advanced's Staffplan Citrix server.

"During the initial logon session, the attacker moved laterally in Advanced's Health and Care environment and escalated privileges, enabling them to conduct reconnaissance, and deploy encryption malware. Immediately prior to encrypting systems, the threat actor copied and exfiltrated a limited amount of data," the October 2022 update said.

There is also the not-so-small matter of the volume of data stolen. Personal data belonging to 82,946 people was lifted, so say the ICO's provisional findings. 

Phone numbers were taken, which isn't great but also not unexpected in a data breach. Medical records were also stolen which, again, isn't very good at all but all the recent attacks on healthcare providers have made this somewhat the norm nowadays.

However, the LockBit affiliate responsible for this one also stole files that included details of how to gain access to the homes of 890 people receiving care at their address.

Advanced found no evidence of this being published online, but blueprints on how to gain access to a vulnerable person's home – that's exactly the kind of data that, in the wrongest of hands, could lead to some grizzly outcomes.

"This incident shows just how important it is to prioritize information security," Edwards said today. "Losing control of sensitive personal information will have been distressing for people who had no choice but to put their trust in health and care organizations. 

"Not only was personal information compromised, but we have also seen reports that this incident caused disruption to some health services, disrupting their ability to deliver patient care. A sector already under pressure was put under further strain due to this incident. 

"For an organization trusted to handle a significant volume of sensitive and special category data, we have provisionally found serious failings in its approach to information security prior to this incident. Despite already installing measures on its corporate systems, our provisional finding is that Advanced failed to keep its healthcare systems secure. We expect all organizations to take fundamental steps to secure their systems, such as regularly checking for vulnerabilities, implementing multi-factor authentication, and keeping systems up to date with the latest security patches. 

  • Five months after takedown, LockBit is a shadow of its former self
  • Major IT outage forces UK emergency call handlers to use 'pen and paper'
  • Emergency services call-handling provider: Ransomware forced it to pull servers offline
  • LockBit 3.0 malware forced NHS tech supplier to shut down hosted sites

"I am choosing to publicize this provisional decision today as it is my duty to ensure other organizations have information that can help them to secure their systems and avoid similar incidents in the future. I urge all organizations, especially those handling sensitive health data, to urgently secure external connections with multi-factor authentication."

The Register approached Advanced for a response but it didn't reply.

At the time of the attack, Advanced had 36 NHS clients using its various wares. Adastra, its clinical patient management system, which is still used by the healthcare services, was among the solutions affected and was used at the time by 85 percent of NHS 111 services. ®

Source: theregister.com

Related stories
5 days ago - I wanna know 🎵 What you're feeling 🎵 Tell me what's on your mind Meta is going to resume scraping the personal public feeds of British Facebook and Instagram users for training AI after reaching an agreement with the UK's Information...
1 month ago - It took 13 months to notice 40 million voters' data was compromised The UK's Electoral Commission has received a formal slap on the wrist for a litany of security failings that led to the theft of personal data belonging to around 40...
2 weeks ago - Selfie-scraper again claims European law does not apply to it The Dutch Data Protection Authority (DPA) has fined controversial facial recognition company Clearview AI €30.5 million ($33 million) over the "illegal" collation of images.…
2 weeks ago - Network admins take a ride on the Fright Bus The Transport for London (TfL) "cyber incident" is heading into its third day amid claims that a popular appliance might have been the gateway for criminals to gain access to the organization's...
1 month ago - The controversy erupted when some eagle-eyed X users noticed a new option buried in the platform's privacy settings to opt-out of having their data used to train Grok. Outrage quickly spread across the platform as users realized their...
Other stories
57 minutes ago - After the last few entries visited historical and near-future time periods, the next Battlefield game will return to a modern-day setting, aiming to recapture the essence of Battlefield 3 and 4. The follow-up recently entered full...
57 minutes ago - The Windows App allows you to access your Windows PC, Azure Virtual Desktop, or Remote Desktop from almost any device. It is available for Windows, Macs, iPhones, iPads, and Android devices. The app supports multiple monitors, USB...
57 minutes ago - Why You Can Trust CNET Our expert, award-winning staff selects the products we cover and rigorously researches and tests our top picks. If you buy...
57 minutes ago - The video game Devil May Cry is getting its own animated Netflix show, and the streaming service revealed a teaser during Geeked Week on Thursday....
57 minutes ago - He's terrier-fying. And you can now change Skelly's spooky eyes to fit in with various holidays.