FBI: Irish HSE hackers targeted 16 US healthcare orgs
Of the 400 organisations worldwide that have been hit by Conti, over 290 are located in the US
The Conti ransomware gang attempted to breach over a dozen US healthcare and first responder organisations, according to the Federal Bureau of Investigations (FBI).
The agency sent out a Traffic Light Protocol (TLP) alert on Thursday to help security teams defend their organisation's networks against future Conti attacks.
It suggested that 16 US services were targeted, including law enforcement agencies, 911 dispatch services and municipalities, all within the last 12 months.
"These healthcare and first responder networks are among the more than 400 organisations worldwide victimised by Conti, over 290 of which are located in the US," the FBI Cyber Division said.
Conti is a type of ransomware as a service (RaaS) operation that is thought to be deployed by a Russian group known as Wizard Spider. It shares some of the same code as the notorious Ryuk strain and has recently been linked to attacks on Ireland's Health Service Executive (HSE) and its Department of Health (DoH).
The DoH was able to prevent the Conti attack from encrypting its network but the HSE was not so lucky and was forced to shut down all its IT systems to prevent it from spreading further.
The US government has previously warned of ransomware attacks on its healthcare industry after Ryuk was used to takedown systems for Universal Health Services in October 2020.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
The consequences of successful ransomware deployment on hospitals were fully realised last year when a man died after his ambulance had to be rerouted due to a Berlin hospital having its systems compromised.
Germany is fearing more attacks too, with its cyber security agency sending out an alert over the weekend that warned of an increased risk of hackers targeting hospitals. The agency's chief, Arne Schoenbohm, told Zeit Online that remote working has led to "a greater danger at hospitals".
Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.
Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.
-
The OpenAI and Anthropic containment breaches are a bit spooky, but also quite sillyOpinion An AI leaving notes to future versions of itself is pure sci-fi; forgetting to lock down an environment is prosaic
-
Bringing data to the heart of AISponsored AI is changing our approach to data, find out how HPE Alletra Storage can help your business
-
Companies are still paying ransoms to cyber criminals despite official adviceNews A Proofpoint survey found evolving ransomware techniques and the use of AI is exacerbating the situation for victims
-
This one cyber crime group accounted for nearly a fifth of all ransomware attacks in JuneNews The Gentlemen, a ransomware a service operator, now accounts for 17% of published attacks
-
Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clientsNews Angelo Martino was supposed to be negotiating on behalf of victims, but was secretly working for ransomware operators
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolenNews An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals