{"id":1223577,"date":"2022-10-13T14:18:28","date_gmt":"2022-10-13T14:18:28","guid":{"rendered":"https:\/\/www.ghanamma.com\/2022\/10\/13\/nhs-vendor-advanced-wont-say-if-patient-data-was-stolen-during-ransomware-attack\/"},"modified":"2022-10-13T14:18:28","modified_gmt":"2022-10-13T14:18:28","slug":"nhs-vendor-advanced-wont-say-if-patient-data-was-stolen-during-ransomware-attack","status":"publish","type":"post","link":"https:\/\/www.ghanamma.com\/2022\/10\/13\/nhs-vendor-advanced-wont-say-if-patient-data-was-stolen-during-ransomware-attack\/","title":{"rendered":"NHS vendor Advanced won&#8217;t say if patient data was stolen during ransomware attack \u2022"},"content":{"rendered":"<p><\/p>\n<div>\n<p id=\"speakable-summary\"><span class=\"featured__span-first-words\">Advanced, an IT service<\/span> provider for the U.K.\u2019s National Health Service (NHS), has confirmed that attackers stole data from its systems during an August ransomware attack, but refuses to say if patient data was compromised.<\/p>\n<p>Advanced first confirmed the ransomware incident on August 4 following widespread disruption to NHS services across the U.K. The attack downed a number of the organization\u2019s services, including its Adastra patient management system, which helps non-emergency call handlers dispatch ambulances and helps doctors access patient records, and Carenotes, which is used by mental health trusts for patient information.<\/p>\n<p>In an update dated October 12 and shared with  on Thursday, Advanced said the malware used in the attack was LockBit 3.0, according to the company\u2019s incident responders, named as Mandiant and Microsoft. LockBit 3.0 is a ransomware-as-a-service (RaaS) operation that hit Foxconn earlier this year.<\/p>\n<p>In its updated incident report, Advanced said that the attackers initially accessed its network on August 2 using \u201clegitimate\u201d third-party credentials to establish a remote desktop session to the company\u2019s Staffplan Citrix server, used for powering its caregiver\u2019s scheduling and rostering system. The report implies that there was no multi-factor authentication in place that would block the use of stolen passwords.<\/p>\n<p>\u201cThe attacker moved laterally in Advanced\u2019s Health and Care environment and escalated privileges, enabling them to conduct reconnaissance, and deploy encryption malware,\u201d Advanced said in the update.<\/p>\n<p>Advanced said some data pertaining to 16 Staffplan and Caresys customers (referring to NHS trusts) was \u201ccopied and exfiltrated,\u201d a technique known as double-extortion, where cybercriminals exfiltrate a company\u2019s data before encrypting the victim\u2019s systems.<\/p>\n<p>In the update, Advanced said there is \u201cno evidence\u201d to suggest that the data in question exists elsewhere outside our control and \u201cthe likelihood of harm to individuals is low.\u201d When reached by , Advanced chief operating officer Simon Short declined to say if patient data is affected, or whether Advanced has the technical means, such as logs, to detect if data was exfiltrated.<\/p>\n<p>Lockbit 3.0\u2019s dark web leak site did not list Advanced or NHS data at the time of writing. Short also declined to say if Advanced paid a ransom.<\/p>\n<p>\u201cWe are, however, monitoring the dark web as a belt and braces measure and will let you know immediately in the unlikely event that this position changes,\u201d Advanced said in the update.<\/p>\n<p>Advanced said its security team disconnected the entire Health and Care environment to contain the threat and limit encryption, which downed a number of services across the NHS. The extended outage left some trusts unable to access clinical notes and others were forced to rely on pen and paper, BBC News reported in August.<\/p>\n<p>Advanced said its recovery from the incident is likely to be slow, citing an assurance process set by the NHS, NHS Digital, and the U.K. National Cyber Security Center.<\/p>\n<p>\u201cThis is time consuming and resource intensive and it continues to contribute to our recovery timeline,\u201d Advanced said. \u201cWe are working diligently and bringing all resources to bear, including outside recovery specialists, to help us restore services to our customers as quickly as possible.\u201d<\/p>\n<p>The healthcare industry remains a top priority for ransomware actors. Earlier this month, U.S. hospital giant CommonSpirit was hit by a cybersecurity incident that is disrupting medical services across the country \u2014 which it later confirmed was a ransomware attack.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Advanced, an IT service provider for the U.K.\u2019s National Health Service (NHS), has confirmed that attackers stole data from its systems during an August ransomware attack, but refuses to say if patient data was compromised. Advanced first confirmed the ransomware incident on August 4 following widespread disruption to NHS services across the U.K. The attack [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1223579,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21],"tags":[],"class_list":["post-1223577","post","type-post","status-publish","format-standard","has-post-thumbnail","category-celebrity-gossip"],"_links":{"self":[{"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/posts\/1223577","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/comments?post=1223577"}],"version-history":[{"count":0,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/posts\/1223577\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/media?parent=1223577"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/categories?post=1223577"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/tags?post=1223577"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}