US, UK hospitals dragged offline by suspected ransomware attack

(Image credit: Shutterstock.com/sfam_photo)

Universal Health Services (UHS), which operates circa 400 healthcare facilities in the UK and US, has confirmed it has suffered a massive cyberattack.

According to employees, the organization’s computer systems have been locked and access to phone systems also affected. Although the precise nature of the attack has not yet been confirmed, all signs point to a ransomware infection.

One individual with direct knowledge of the situation explained that affected UHS computers began to serve up text that referred to “shadow universe” - a hallmark of Ryuk ransomware, operated by Russian cybercriminal syndicate Wizard Spider.

“Everyone was told to turn off all the computers and not to turn them on again. We were told it will be days before the computers are up again,” they said.

Despite the outages and temporary switch to “offline documentation methods”, UHS insists  that “patient care continues to be delivered effectively”.

UHS ransomware attack

The ransomware is said to have taken hold over the weekend, potentially after an extended period laying dormant in UHS systems, but the organization claims to have a handle on the situation.

“The IT Network across Universal Health Services (UHS) facilities is currently offline, due to an IT security issue,” explained the firm in a statement.

“We implement extensive IT security protocols and are working diligently with our IT security partners to restore IT operations as quickly as possible. In the meantime, our facilities are using their established back-up processes.”

The firm also asserts that no patient or employee data has been accessed, copied or misused, which is surprising given the proclivity of ransomware operators to exfiltrate data before encrypting IT systems, to use as leverage.

Hospitals have become an increasingly popular target for cybercriminals, due to the high volume of personally identifiable information (PII) in storage, as well as the high stakes nature of the industry.

For example, hackers recently launched a ransomware attack on a German hospital, leading to the death of a woman who had to be rerouted to a separate facility 20 miles away. The incident is being treated as a homicide.

Another hospital in the Czech Republic was forced to suspend operations and shift patients to an alternative facility after an attack.

Some ransomware operators pledged not to target healthcare facilities at the height of the pandemic, during which period hospitals were overwhelmed with an influx of patients. Other malicious actors, including Ryuk, offered no such promises.

We will update this article as new information emerges.

Via TechCrunch

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras