To specifically target hospitals and healthcare with ransomware is pure evil
[See the full post at: Patch Lady – make sure you are protected]
Susan Bradley Patch Lady/Prudent patcher
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
Home » Forums » Newsletter and Homepage topics » Patch Lady – make sure you are protected
Tags: Patch Lady Posts
To specifically target hospitals and healthcare with ransomware is pure evil
[See the full post at: Patch Lady – make sure you are protected]
Susan Bradley Patch Lady/Prudent patcher
This has been going on for a while. I posted about it here: https://www.askwoody.com/forums/topic/over-400-hospitals-hacked-in-the-us-this-weekend/
At the time this was the only mention on it by any of the news: https://www.nbcnews.com/tech/security/cyberattack-hits-major-u-s-hospital-system-n1241254
Was a little surprised it received so little media attention and nothing on here until now. It is the largest attack in US history. Three of the four Hospitals in my area (Temecula, CA) were affected by it. They had to go back to full paper. I heard that they still haven’t fully recovered. This week the fourth hospital was down as well for this latest attack.
Windows 8.1 Group B, Brave & Mozilla ESR - grudgingly & Protonmail
In September, the first known patient to die as a result of malware, died in Germany because the computers at the closest hospital were down. She needed urgent care but had to be brought to a hospital 20 miles away. Doctors were not able to start treating her for an hour and she died. https://apnews.com/article/technology-hacking-europe-cf8f8eee1adcec69bcc864f2c4308c94
Windows 8.1 Group B, Brave & Mozilla ESR - grudgingly & Protonmail
@Erik It was a good thing you tried to bring this to the attention of AskWoody members. I see there were no responses to the original posts – maybe because they were posted to “The Junk Drawer” which is probably not widely read here. They may have raised more eyebrows had they been posted to the “Code Red – Security/Privacy advisories” section. Appreciate the good intentions, though!
Win10 Pro x64 22H2, Win10 Home 22H2, Linux Mint + a cat with 'tortitude'.
It does make you think about bringing back public flogging, doesn’t it? It’s enough to make me think about forswearing my species and declare myself a Gorilla.
Awful, just awful. Right next to bombing said institutions, the perps should be made to stand trial for Crimes against Humanity.
Win7 Pro SP1 64-bit, Dell Latitude E6330 ("The Tank"), Intel CORE i5 "Ivy Bridge", 12GB RAM, Group "0Patch", Multiple Air-Gapped backup drives in different locations. Linux Mint Newbie
--
"The more kinks you put in the plumbing, the easier it is to stop up the pipes." -Scotty
“lowest possible cost” model
this new version is very populair here too, ‘-(
“Lowest possible cost” model, expanded to the game of “I Know Better”
These criminals targeting hospitals and other facilities that people need are just awful. Hackers are in lead by a step at everytime, cause OS vendor has to react to newly discvered vulnerabilities and it takes some time to patch these holes.
Every chain is as strong as its weakest fragment. Same with IT. It takes just one “expert” to bring infection to your system/domain/whatecer.
Thanks for sharing this information! I have only one advice. These following steps should be done in reverse order
I’ve installed the October patches.
I’ve checked to make sure backups are working (and not backing up to a drive that is accessible by the user making the backup – look to your backup vendor/ask them if their solution does this).
Dell Latitude 3420, Intel Core i7 @ 2.8 GHz, 16GB RAM, W10 22H2 Enterprise
HAL3000, AMD Athlon 200GE @ 3,4 GHz, 8GB RAM, Fedora 29
PRUSA i3 MK3S+
Thunderbird is good at stopping trackers and drive-bys, but it can’t prevent you being phished or downloading and running malware. We humans are suckers for flashy new get rich quick schemes, this is the reason the bad guys are successful.
cheers, Paul
One aspect confuses me. I make frequent image backups.
If I get hit by Ransomware, my understanding is that I can recover by restoring from a backup. So, why can’t hospitals and businesses do the same?
Also, I save my images on an ext. HD, which I keep in my safe deposit box. The HD is never connected to my computer, other than when I’m doing my image B/U. What is wrong with that?
Mel (Acer laptop, W10 ver 2004)
All problems cant be solved by restoring. Data are safe, but..
At home, restoring PC from backup will restore your PC exactly as it was some time ago (If you dont use Windows in-built restore points which manages to do exactly NOTHING), but not with enterprise infrastructure: with AD, DC, FS, Exchange, application servers, SQL servers, WSUS, …
Its just too comlicated to be backed up on “one tape”
Dell Latitude 3420, Intel Core i7 @ 2.8 GHz, 16GB RAM, W10 22H2 Enterprise
HAL3000, AMD Athlon 200GE @ 3,4 GHz, 8GB RAM, Fedora 29
PRUSA i3 MK3S+
So, why can’t hospitals and businesses do the same?
Mainly because they don’t do backups.
Mainly because they don’t do backups.
I know my credit union does off-site backups and would be back up and running within hours.
Mel
… or that their backup procedure is a bad fit for their situation.
Especially the part about testing that the backup can be restored…
Also, in a complex enterprise environment, a full restore is sort of expensive anyway (at least if the local regulations require full testing afterwards, which is not unreasonable on the face of it but the full procedure might take a week or two…), so by math if the ransom is less than the total cost of restoring from backup and…
I just can’t figure out what kind of math would allow them to not do the full testing and recertification anyway after paying the ransom.
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.
Notifications