{"id":36467,"date":"2022-02-09T15:00:16","date_gmt":"2022-02-09T15:00:16","guid":{"rendered":"https:\/\/www.vmengine.net\/2022\/02\/09\/conti-ransomware-when-cyber-prevention-protects-literally-your-data\/"},"modified":"2025-05-23T17:32:55","modified_gmt":"2025-05-23T17:32:55","slug":"conti-ransomware-when-cyber-prevention-protects-literally-your-data","status":"publish","type":"post","link":"http:\/\/temp_new.vmenginelab.com\/en\/2022\/02\/09\/conti-ransomware-when-cyber-prevention-protects-literally-your-data\/","title":{"rendered":"Conti ransomware, when cyber prevention protects (literally) your data"},"content":{"rendered":"<div class=\"et_pb_section et_pb_section_367 et_section_regular\" >\n<div class=\"et_pb_row et_pb_row_465\">\n<div class=\"et_pb_column et_pb_column_4_4 et_pb_column_471  et_pb_css_mix_blend_mode_passthrough et-last-child\">\n<div class=\"et_pb_module et_pb_text et_pb_text_1586  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p>It was May last year when the Irish healthcare system was attacked by the most well-known and feared <strong>ransomware<\/strong> in the<strong> cyberthreat<\/strong> landscape: <strong>Conti<\/strong>.<\/p>\n<p>It is the<strong> &#8220;human-operated&#8221; ransomware that<\/strong>has been breaking into corporate networks for more than a year. After stealing sensitive data and encrypting it, the perpetrators threaten their victims to make it visible on the &#8220;<strong>Conti News<\/strong>&#8221; website if the demanded ransom is not paid. This is more or less what happened in May 2021 to the<strong> healthcare system<\/strong> of one of the most advanced European countries. As a precaution, the agency had shut down all of its IT systems &#8220;<em>in order to protect them and allow us to fully assess the situation with security partners<\/em>.&#8221; They wrote in a press release. It was a real <strong>criminal operation<\/strong> orchestrated at the international level, a very sophisticated attack that affected all <strong>local and national systems<\/strong>.<\/p>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_image et_pb_image_416\">\n<p>\t\t\t\t<span class=\"et_pb_image_wrap \"><img decoding=\"async\" src=\"http:\/\/temp_new.vmenginelab.com\/wp-content\/uploads\/2022\/02\/ran-hospital-2.jpg\" alt=\"\" title=\"RAN Hospital\"  sizes=\"(max-width: 740px) 100vw, 740px\" class=\"wp-image-34580\" \/><\/span>\n\t\t\t<\/div>\n<div class=\"et_pb_module et_pb_cta_339 et_pb_promo  et_pb_text_align_center et_pb_bg_layout_light\">\n<div class=\"et_pb_promo_description et_multi_view_hidden\"><\/div>\n<div class=\"et_pb_button_wrapper\"><a class=\"et_pb_button et_pb_promo_button\" href=\"https:\/\/temp_new.vmenginelab.com\/2021\/07\/30\/quando-la-cyber-security-diventa-un-affare-di-stato\/\" target=\"_blank\">When cyber security becomes a &quot;state affair<\/a><\/div>\n<\/p><\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1587  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p>So, a few days ago, the <a href=\"https:\/\/www.dhs.gov\/\"><br \/>\n  <strong>U.S. Department of Health and Human Services<\/strong><br \/>\n<\/a> published a note that paints a grim picture of what happened. The healthcare system has<strong> been literally overwhelmed<\/strong>. Clearly, the <strong>consequences have been devastating<\/strong> for the health system and especially for citizens, even more so with a <strong>Covid-19<\/strong> pandemic in the middle. This has led to major disruptions to health services across <strong>Ireland<\/strong> as well as stealing the information of thousands of Irish people, including protected health information.<br \/>The incident report, commissioned by the Irish <strong><br \/>\n  <a href=\"https:\/\/www.hse.ie\/eng\/\">HSE<\/a><br \/>\n<\/strong> Council in June 2021, reveals that the impact of this attack on the IT environment was mainly caused by a <b>lack of prevention<\/b><span style=\"font-weight: 400;\">. <\/span> <\/p>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1588  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p>From what emerges from the analysis of the incident, the HSE did not have a <strong>cybersecurity<\/strong> manager,<em> &#8220;there were no IT security managers or managers at the time of the incident. There was no dedicated committee to provide direction and oversight of the activities needed to reduce cyber risk exposure.&#8221;<\/em><br \/>And that&#8217;s not all. &#8220;<em>The HSE did not have a centralized cybersecurity function that managed cybersecurity risks and controls.&#8221;<\/em><br \/>To top it off, <strong>no security monitoring<\/strong> solutions have been implemented to help investigate and respond to security threats detected in the IT environment.<\/p>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_image et_pb_image_417\">\n<p>\t\t\t\t<span class=\"et_pb_image_wrap \"><img decoding=\"async\" src=\"http:\/\/temp_new.vmenginelab.com\/wp-content\/uploads\/2022\/02\/he-2.jpg\" alt=\"\" title=\"\"  sizes=\"(max-width: 740px) 100vw, 740px\" class=\"wp-image-34585\" \/><\/span>\n\t\t\t<\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1589  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p>The digital bandits provided the Irish healthcare system with a <strong>free decryptor<\/strong> to restore the systems. Poor consolation. However, they made it clear that they would sell or publish the stolen data if the <strong>HSE<\/strong> did not pay a ransom of <strong>as much as $20 million<\/strong>.  <em>&#8220;We are providing the decryption tool for your network for free. &#8211;  <\/em>they wrote coldly in<em> the chat -But you should understand that we will sell or publish a lot of private data if you don&#8217;t try to resolve the situation.&#8221;<\/em> In short, forewarned is forearmed. This is how the gang of criminals 2.0 operated.<\/p>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1590  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p>But the government did not bow to blackmail and although the incident led to widespread disruption in Irish health services, Taoiseach Miche\u00e1l Martin, the Irish Prime Minister, said the HSE would not pay any ransom. So the stolen files were uploaded to &#8220;<strong>VirusTota<\/strong>l&#8221;. An Irish court subsequently ordered VirusTotal to provide any information about subscribers who downloaded or uploaded confidential data (including email addresses, phone numbers, IP addresses, or physical addresses) stolen from Ireland&#8217;s national health network.<\/p>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_cta_340 et_pb_promo  et_pb_text_align_center et_pb_bg_layout_light\">\n<div class=\"et_pb_promo_description et_multi_view_hidden\"><\/div>\n<div class=\"et_pb_button_wrapper\"><a class=\"et_pb_button et_pb_promo_button\" href=\"https:\/\/temp_new.vmenginelab.com\/2021\/11\/10\/attacchi-informatici-a-napoli-nasce-threat-hunting-investigation-competence-centre\/\" target=\"_blank\">Cyber attacks, Threat Hunting &amp; Investigation Competence Centre is born in Naples<\/a><\/div>\n<\/p><\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1591  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p>This story leaves a bitter taste in the mouth because the stolen files were<strong> downloaded 23 times<\/strong> by VirusTotal subscribers before the service removed it on <strong>May 25, 2021<\/strong>. The moral of the story is that it would have taken very little to keep thousands of citizens safe: an effective prevention system and adequate professionals.<\/p>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>In May 2021, Ireland&#8217;s healthcare system was attacked: a disaster that could have been avoided<\/p>\n","protected":false},"author":3,"featured_media":34591,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[97,2297,1374],"tags":[4285,4154,4793,4652,1270],"class_list":["post-36467","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-en","category-news-en","category-the-analysis","tag-cybersecurity-en","tag-hacker-attack","tag-irish-hse","tag-ransomware-en","tag-security-en"],"aioseo_notices":[],"jetpack_featured_media_url":"http:\/\/temp_new.vmenginelab.com\/wp-content\/uploads\/2022\/02\/gif-2-ran-1.gif","amp_enabled":true,"_links":{"self":[{"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/posts\/36467","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/comments?post=36467"}],"version-history":[{"count":1,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/posts\/36467\/revisions"}],"predecessor-version":[{"id":41691,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/posts\/36467\/revisions\/41691"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/media\/34591"}],"wp:attachment":[{"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/media?parent=36467"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/categories?post=36467"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/tags?post=36467"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}