NHS data stolen from contractor in serious cyberattack

password manager security
(Image credit: Passwork)

NHS software vendor Advanced has confirmed it suffered a ransomware attack that resulted in the theft of sensitive customer data. 

The company says an unknown threat actor used “legitimate third-party credentials” which gave them the ability to establish a remote desktop (RDP) session to the Staffplan Citrix server. 

From there, the attackers moved laterally throughout the network, escalating privileges where necessary to map the entire network, identify crucial endpoints, as well as pivotal data. 

Cutting out the attackers

Two days later, after exfiltrating enough sensitive files, the group deployed LockBit 3.0, a known and potent ransomware variant that encrypted all of the data on the network. 

Advanced said the group was financially motivated, but did not detail how much money it demanded for the decryption key and the return of data, nor whether or not it paid.

As soon as Advanced realized it was being attacked, it disconnected all of its systems from the internet. 

While that stopped further escalation of the attack, it also temporarily prevented customers and users from accessing the systems. As a result, the company then proceeded to re-establish the network in a “separate, secure, and new environment.”

In total, the company claims that 16 customers have had their sensitive information stolen. It did not say exactly what this data included, but it did say that the victims were notified in a timely fashion, and that it managed to restore all of the stolen info.

Further describing the recovery process, Advanced said it was able to move relatively fast, but still needed to satisfy government processes. 

“Although we were equipped and able to completely rebuild certain health and care products by the Monday following the incident, we were required to satisfy an assurance process set forth by our partners at the NCSC, NHS, and NHS Digital.”

It said that this process proved to be time-consuming, and cumbersome.

“As we learned more about this assurance process and adjusted in real time to meet certain requirements, it took longer than expected, which has impacted our overall recovery timeline. We have prioritized safety and security during every step of our recovery process,” it was said. 

“As we work through scanning and clearing systems, we are in parallel continuing to assess and/or develop recovery plans for remaining impacted products,” it concluded.

Via: DigitalHealth

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
security
Ransomware gangs allegedly hit two major US healthcare firms, 300,000 patients have data stolen
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
UK private health services firm told to pay up $2m for ransomware hit
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
ransomware avast
The biggest addiction treatment provider in the US says it was hit by data breach
ID theft
Over a million patients potentially hit after another US healthcare provider hit by cyberattack
An abstract image of padlocks overlaying a digital background.
US healthcare giant Ascension says ransomware attack affected nearly six million customers
Latest in Security
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
3d rendering of a submarine power cable on the seabed
Subsea internet cables can now ‘listen’ for sabotage using irregular pulses of light
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
Latest in News
A woman sitting in a chair looking at a Windows 11 laptop
Microsoft is supercharging Windows 11’s voice commands on Copilot+ PCs with Snapdragon CPUs, and fine-tuning a few Recall features
The Future Games Show Spring Showcase
The Future Games Show returns this week for its Spring Showcase, here's how to watch and what games to expect
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
Apple iPhone 16 Plus Review
Apple expert just tipped a load of iPhone 17 upgrades: here are 7 things we’ve learned
Google Chromecast 2
Google rolls out another Chromecast bug fix for users who factory-reset their devices