IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Irish police seize Conti domains used in HSE ransomware attack

The Garda’s cyber crime unit confirmed that it had disrupted the hacking gang's IT infrastructure

Ireland’s Garda National Cyber Crime Bureau has announced that it had “seized several domains” used in the ransomware attack on the Irish Health Service Executive (HSE) earlier this year.

The attack, which took place in mid-May, forced the national health and social services provider to shut down its entire IT system, which lead to appointments being delayed or cancelled. The Irish Department of Health was also targeted but managed to prevent Conti from encrypting its network.

On Sunday, almost four months after the attack, the Garda’s cyber crime unit confirmed that it had disrupted the IT infrastructure of the Conti hacking group, which had claimed responsibility for the attack. Thought to be deployed by a Russian group known as Wizard Spider, Conti functions as a type of ransomware as a service (RaaS) operation.

“The Garda National Cyber Crime Bureau have seized several domains used in this and other ransomware attacks,” a Garda spokesperson told IT Pro, adding that the seizure “has directly prevented a large number of further ransomware attacks across the world”.

The Bureau has also notified potential victims of the ransomware gang and is working with Europol and Interpol to ensure that other states are aware of the systems targeted by Conti.

Related Resource

The ultimate law enforcement agency guide to going mobile

Best practices for implementing a mobile device program

Policeperson tapping ID to phone with car in the background - whitepaper from SamsungFree download

A Garda spokesperson described the operation as “crime prevention”, adding that to date there had been “a total of 753 attempts (...) made by ICT systems across the world to connect to the seized domains”. 

“In each instance, the seizure of these domains by the GNCCB investigation team is likely to have prevented a Conti Ransomware Attack on the connecting ICT system, by rendering the initially deployed malware on the victims system, as ineffective,” they said.

HSE wasn’t the only healthcare provider targeted by the Conti ransomware group. Days after the attack was reported, the US Federal Bureau of Investigations (FBI) found that the ​​gang had also attempted to breach 16 US services, including law enforcement agencies, 911 dispatch services and municipalities, with the attempted attacks all taking place since May 2020.

The FBI Cyber Division stated that the targeted healthcare and first responder networks were “among the more than 400 organisations worldwide victimised by Conti”, out of which “over 290” are based in the US.

Featured Resources

The Total Economic Impact™ Of Turbonomic Application Resource Management for IBM Cloud® Paks

Business benefits and cost savings enabled by IBM Turbonomic Application Resource Management

Free Download

The Total Economic Impact™ of IBM Watson Assistant

Cost savings and business benefits enabled by Watson Assistant

Free Download

The field guide to application modernisation

Moving forward with your enterprise application portfolio

Free Download

AI for customer service

Discover the industry-leading AI platform that customers and employees want to use

Free Download

Recommended

Cyber resiliency and end-user performance
Whitepaper

Cyber resiliency and end-user performance

17 Aug 2022
Can't choose between public and private cloud? You don't have to with IaaS
Whitepaper

Can't choose between public and private cloud? You don't have to with IaaS

12 Aug 2022
Ransomware now strikes one in 40 organisations per week, Check Point finds
ransomware

Ransomware now strikes one in 40 organisations per week, Check Point finds

27 Jul 2022
What is zero trust?
network security

What is zero trust?

14 Jul 2022

Most Popular

Why convenience is the biggest threat to your security
Sponsored

Why convenience is the biggest threat to your security

8 Aug 2022
How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

29 Jul 2022
UK water supplier confirms hack by Cl0p ransomware gang
ransomware

UK water supplier confirms hack by Cl0p ransomware gang

16 Aug 2022