(844) 627-8267
(844) 627-8267

Russian cyber hacking gang Qilin behind ransomware attack that sparked major chaos at three London hospitals | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


  • King’s College Hospital, Guy’s and St Thomas’ were hit by ransomware attack
  • Has YOUR treatment been affected? Email [email protected]



A Russian cyber hacking gang is behind the ransomware attack that sparked major chaos at three London hospitals, the former chief executive of the National Cyber Security Centre has said.

Ciaran Martin said the attack on pathology services firm Synnovis has led to a ‘severe reduction in capacity’ and ‘it’s a very, very serious incident’.

Hospitals declared a critical incident after the attack and have cancelled operations and tests and been unable to carry out blood transfusions.

Memos to NHS staff at King’s College Hospital, Guy’s and St Thomas’, including the Royal Brompton and the Evelina London Children’s Hospital and primary care services in the capital said there had been a ‘major IT incident’.

Asked on BBC Radio 4’s Today programme if it is known who attacked Synnovis, Mr Martin said: ‘Yes. We believe it is a Russian group of cyber criminals who call themselves Qilin.’

Memos to NHS staff at King’s College Hospital, Guy’s and St Thomas’, including the Royal Brompton and the Evelina London Children’s Hospital and primary care services in the capital said there had been a ‘major IT incident’
Mr Martin said it is ‘unlikely’ the Russian hackers would have known they would cause such serious primary healthcare disruption when they set out to do the attack
Ciaran Martin said the attack on pathology services firm Synnovis has led to a ‘severe reduction in capacity’ and ‘it’s a very, very serious incident’

‘These criminal groups – there are quite a few of them – they operate freely from within Russia, they give themselves high-profile names, they’ve got websites on the so-called dark web, and this particular group has about a two-year history of attacking various organisations across the world.

‘They’ve done automotive companies, they’ve attacked the Big Issue here in the UK, they’ve attacked Australian courts. They’re simply looking for money.’

He said it is ‘unlikely’ the Russian hackers would have known they would cause such serious primary healthcare disruption when they set out to do the attack.

Click here to resize this module

He added: ‘There are two types of ransomware attack. One is when they steal a load of data and they try and extort you into paying so that isn’t released, but this case is different. It’s the more serious type of ransomware where the system just doesn’t work.

‘So, if you’re working in healthcare in this trust, you’re just not getting those results so it’s actually seriously disruptive.

‘This type of ransomware has affected healthcare all over the world.

‘It’s particularly damaging in the United States, and where this type of cyber attack is different in terms of its impact from others, is that it does affect people’s healthcare. So it’s really one of the more serious that we’ve seen in this country.’

One patient, Oliver Dowson, 70, was prepared for an operation from 6am on Monday June 3 at the Royal Brompton Hospital when he was told by a surgeon at about 12.30pm that it would not be going ahead.

He said: ‘The staff on the ward didn’t seem to know what had happened, just that many patients were being told to go home and wait for a new date.

‘I’ve been given a date for next Tuesday and am crossing my fingers – it’s not the first time that they have cancelled, they did it on May 28 too, but that was probably staff shortages in half-term week.’

Vanessa Welham, from Streatham, south-west London, said her husband’s blood test at Gracefield Gardens health centre was cancelled on Monday evening and he was informed that local centres were not taking bookings for an ‘indefinite period of time’.

Mr Martin said: ‘They’ve [Qilin] done automotive companies, they’ve attacked the Big Issue here in the UK, they’ve attacked Australian courts. They’re simply looking for money’
Health Secretary Victoria Atkins said on Tuesday that her ‘absolute priority is patient safety’

He said the Government has a policy of not paying but the company would be free to pay the ransom if it chose to.

Regarding patient data, he said: ‘It’s not really a question of data in this one, it’s a question of the services.

Click here to resize this module

‘The criminals are threatening to publish data, but they always do that. Here the priority is the restoration of services.’

Synnovis is a provider of pathology services and was formed from a partnership between SynLab UK & Ireland, Guy’s and St Thomas’ NHS Foundation Trust and King’s College Hospital NHS Foundation Trust.

Some procedures and operations at the hospitals have been cancelled or have been redirected to other NHS providers as hospital bosses establish what work can be carried out safely.

NHS officials said they are working with the National Cyber Security Centre to understand the impact of the attack.

Synnovis said the incident has been reported to law enforcement and the Information Commissioner.

Health Secretary Victoria Atkins said on Tuesday that her ‘absolute priority is patient safety’.

Ms Atkins wrote on X: ‘Throughout yesterday I had meetings with NHS England and the National Cyber Security Centre to oversee the response to the cyber attack on pathology services in south-east London.

‘My absolute priority is patient safety and the safe resumption of services in the coming days.’

A spokesman for NHS England London region said Monday’s attack was ‘having a significant impact’ on the delivery of services at Guy’s and St Thomas’, King’s College Hospital NHS Foundation Trust and primary care services in south-east London.

‘We are working urgently to fully understand the impact of the incident with the support of the Government’s National Cyber Security Centre and our cyber operations team.’

Synnovis chief executive Mark Dollar said on Monday that a taskforce of IT experts from Synnovis and the NHS was working to fully assess the impact and what action is needed.

‘Regrettably, this is affecting patients, with some activity already cancelled or redirected to other providers as urgent work is prioritised,’ he said.

——————————————————–


Click Here For The Original Story From This Source.

.........................

National Cyber Security

FREE
VIEW