{"id":594728,"date":"2023-01-06T09:52:00","date_gmt":"2023-01-06T15:52:00","guid":{"rendered":"https:\/\/news.sellorbuyhomefast.com\/index.php\/2023\/01\/06\/lockbit-ransomware-group-apologizes-for-childrens-hospital-cyberattack\/"},"modified":"2023-01-06T09:52:00","modified_gmt":"2023-01-06T15:52:00","slug":"lockbit-ransomware-group-apologizes-for-childrens-hospital-cyberattack","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2023\/01\/06\/lockbit-ransomware-group-apologizes-for-childrens-hospital-cyberattack\/","title":{"rendered":"LockBit ransomware group &#8216;apologizes&#8217; for children&#8217;s hospital cyberattack"},"content":{"rendered":"<div property=\"content:encoded\">\n<p>The Hospital for Sick Children announced on New Year&#8217;s Day that it was aware of a statement issued by a ransomware group with an apology and an offer of a free decryptor to restore systems impacted by ransomware.<\/p>\n<p><strong>WHY IT MATTERS<\/strong><\/p>\n<p>On December 18, 2022, SickKids was hit with ransomware and operations went to &#8220;Code Grey,&#8221; according to an announcement on the hospital&#8217;s website.\u00a0<\/p>\n<p>&#8220;Clinical teams are currently experiencing delays with retrieving lab and imaging results, which may cause longer wait times for patients and families,&#8221; the hospital said on December 22.<\/p>\n<p>Other affected systems included employee timekeeping and pharmacy submissions.\u00a0<\/p>\n<p>On December 29, the Toronto hospital announced that nearly half of the affected systems had been restored.<\/p>\n<p>According to Globalnews.ca, the LockBit ransomware group that provides affiliates access to malware for a cut of the ransom profits then issued an apology on the dark web on the last day of the year, which was then\u00a0<a data-mce-href=\"https:\/\/twitter.com\/AlvieriD\/status\/1609253113436700678?s=20&#038;t=hLelspGcmLxOXfsYyHJxGg\" href=\"https:\/\/twitter.com\/AlvieriD\/status\/1609253113436700678?s=20&#038;t=hLelspGcmLxOXfsYyHJxGg\" target=\"_blank\" rel=\"noopener\">posted to Twitter<\/a>.<\/p>\n<p>In the statement, the ransomware organization allegedly blamed a partner and offered a free decryptor for the hospital to unlock its data.<\/p>\n<p>Even with a ransomware group&#8217;s decryptor, healthcare organizations only recover on average about two-thirds of their files, said Chester Wisniewski, a Vancouver-based principal research scientist with Sophos, according to the news\u00a0<a data-mce-href=\"https:\/\/globalnews.ca\/news\/9382632\/ransomware-group-sickkids-attack\/\" href=\"https:\/\/globalnews.ca\/news\/9382632\/ransomware-group-sickkids-attack\/\" target=\"_blank\" rel=\"noopener\">report<\/a>.\u00a0<\/p>\n<p>Affiliates have a tendency to scramble data, he said.<\/p>\n<p>The purpose of LockBit&#8217;s now-viral statement could be to discourage other affiliates that might see attacking a children&#8217;s hospital as an overstep from defecting to another ransomware group, Wisniewski added.<\/p>\n<p>SickKids posted an additional\u00a0<a data-mce-href=\"https:\/\/www.sickkids.ca\/en\/news\/archive\/2022\/sickkids-aware-of-and-assessing-decryptor-following-cybersecurity-incident\/\" href=\"https:\/\/www.sickkids.ca\/en\/news\/archive\/2022\/sickkids-aware-of-and-assessing-decryptor-following-cybersecurity-incident\/\" target=\"_blank\" rel=\"noopener\">statement<\/a>\u00a0to its website that it was aware of the group&#8217;s apology and is analyzing the decryptor. The hospital also said it did not make a ransom payment, and that there is no evidence to date that personal information or personal health information has been impacted.\u00a0<\/p>\n<p>Brett Callow, a threat analyst with anti-malware company Emsisoft, told the Canadian newsgroup that there is still the question if the allegedly cut-off LockBit affiliate partner still has the hospital&#8217;s data.<\/p>\n<p>A spokesman from the Communications Security Establishment noted in the story that more than 400 healthcare organizations in Canada and the United States have experienced a ransomware attack since March 2020.<\/p>\n<p><strong>THE LARGER TREND<\/strong><\/p>\n<p>In 2021, the Health Sector Cybersecurity Coordination Center released a 31-page briefing on LockBit, its launch of the\u00a0<a data-mce-href=\"https:\/\/www.healthcareitnews.com\/news\/hhs-cybersecurity-agency-sounds-alarm-lockbit-ransomware-variant\" href=\"https:\/\/www.healthcareitnews.com\/news\/hhs-cybersecurity-agency-sounds-alarm-lockbit-ransomware-variant\" target=\"_blank\" rel=\"noopener\">LockBit 2.0 affiliate program<\/a>\u00a0and its recruiting efforts for its ransomware-as-a-service program.<\/p>\n<p>&#8220;The only thing you have to do is to get access to the core server, while LockBit 2.0 will do all the rest,&#8221; according to LockBit&#8217;s documentation that HC3 had obtained.<\/p>\n<p>Through an interview with a LockBit ransomware operator, the cybersecurity arm of the U.S. Department of Health and Human Services indicated that the cyber gang has a measure of ethics.\u00a0<\/p>\n<p>It won&#8217;t operate in certain states like Belarus and Russia for having &#8220;a contradictory code of ethics,&#8221; and may have disdain for those who attack healthcare entities, said HC3.<\/p>\n<p>However, &#8220;While threat actors may state publicly that their personal ethics influence their target selection, many adversaries go after the easiest victims regardless of any moral obligation, based on our experience,&#8221; according to the briefing.<\/p>\n<p>Healthcare cybersecurity experts encourage the industry to\u00a0<a data-mce-href=\"https:\/\/www.healthcareitnews.com\/video\/cybercrime-service-rise-heres-how-fight-back\" href=\"https:\/\/www.healthcareitnews.com\/video\/cybercrime-service-rise-heres-how-fight-back\" target=\"_blank\" rel=\"noopener\">fight cybercrime-as-a-service with security collaboration<\/a>\u00a0because lives \u2013 like those at SickKids \u2013 suffer the diversions of care that inevitably follow ransomware attacks.\u00a0<\/p>\n<p><strong>ON THE RECORD<\/strong><\/p>\n<p>&#8220;These attacks can sometimes originate much closer to home than we realize,&#8221; Callow told Canadian news.\u00a0<\/p>\n<p>&#8220;We think the attacks are coming in from Russia or Commonwealth of Independent States countries, whereas in some cases they could be originating from within our own border,&#8221; he said, noting that LockBit malware was connected to recent ransomware attacks on two small municipal governments \u2013 St. Mary\u2019s, Ontario, and Westmount, Quebec.<\/p>\n<p><em>Andrea Fox is senior editor of Healthcare IT News.<br \/>\nEmail:\u00a0<a href=\"http:\/\/www.healthcareitnews.com\/mailto:af**@***ss.org\" data-original-string=\"1y5sdhZ+dJG+s4gyowRKpA==7f4z9RF0EiFn94wQTuj7lR1HA==\" title=\"This contact has been encoded by Anti-Spam by CleanTalk. Click to decode. To finish the decoding make sure that JavaScript is enabled in your browser.\" target=\"_blank\" rel=\"noopener\"><span \n                data-original-string='0CN01cdd5E9fj6NGTTdsMA==7f4VK2mivj0Ru6wDWGH87fnrA=='\n                class='apbct-email-encoder'\n                title='This contact has been encoded by Anti-Spam by CleanTalk. Click to decode. To finish the decoding make sure that JavaScript is enabled in your browser.'>af<span class=\"apbct-blur\">**<\/span>@<span class=\"apbct-blur\">***<\/span>ss.org<\/span><\/a><\/em><br \/><em>Healthcare IT News is a HIMSS publication.<\/em><\/p>\n<\/div>\n<p><a href=\"https:\/\/www.healthcareitnews.com\/news\/lockbit-ransomware-group-apologizes-childrens-hospital-cyberattack\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><br \/>\n Larisa Paris<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Hospital for Sick Children announced on New Year&#8217;s Day that it was aware of a statement issued by a ransomware group with an apology and an offer of a free decryptor to restore systems impacted by ransomware. WHY IT MATTERS On December 18, 2022, SickKids was hit with ransomware and operations went to &#8220;Code<\/p>\n","protected":false},"author":1,"featured_media":594729,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[36389,31358],"tags":[],"class_list":{"0":"post-594728","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-lockbit","8":"category-ransomware"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/594728","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=594728"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/594728\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/594729"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=594728"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=594728"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=594728"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}