Access to employees’ email accounts, and then pivoted to specifically target login information related to the processing of reimbursement payments to insurance companies, medicare, or similar entities.
To gain initial access to victim networks, the threat actor acquired credentials through social engineering or phishing. In some observed instances, the threat actor called an organization’s IT Help Desk posing as an employee of the organization, and triggered a password reset for the targeted employee’s organizational account [T1566.004]. In some instances, by manipulating the IT Help Desk employees, the threat actor was able to bypass multifactor authentication (MFA) [T1556.006]. In another instance, the threat actors registered a phishing domain [T1556.001] that varied by one character from the target organization’s true domain, and targeted the organization’s Chief Financial Officer (CFO) [TA1656].
Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division
Related:
- Europol director calls on ‘all sectors’ to take cyber security threat seriously
May 14, 2017
The malware attack that paralysed parts of the NHS shows that “all sectors” should take cyber security “absolutely seriously”, the director of Europol has said, Speaking on ITV’s Peston on Sunday, Rob Wainwright warned the healthcare sector “in many countries” was particularly vulnerable, but that all organisations should ensure they prioritised cyber security and updated their ...
- The government slashed NHS IT security contract despite warnings it would leave systems vulnerable to cyberattack
May 13, 2017
The UK government were repeatedly warned that NHS IT isystems were running on outdated operating systems that were vulnerable to attack, yet failed to ensure they were protected. Freedom of Information requests last sumer revealed that trusts across the country were still using Windows XP, despite a government contract with Microsoft to update protections for the system having ...
- UK hospital meltdown after ransomware worm uses NSA vulnerability to raid IT
May 12, 2017
UK hospitals have effectively shut down and are turning away non-emergency patients after ransomware ransacked its networks. Some 16 NHS organizations across Blighty – including several hospital trusts such as NHS Mid-Essex CCG and East and North Hertfordshire – have had their files scrambled by a variant of the WannaCrypt, aka WanaCrypt aka Wcry, nasty. Users ...
- Cyber security: an ‘indigestion problem’ in healthcare industry
May 11, 2017
In August 2011, Marc Andreessen famously wrote an essay in The Wall Street Journal, “Why Software is Eating the World”. It talked about the growing significance of software in business across a wide swathe of industries. Fast forward to the present day in 2017 and we can safely say that the process of eating is ...
- Prognosis For Healthcare Cybersecurity Is Dire
April 6, 2017
On Wednesday (April 5), Terence Rice, VP and chief information security officer at Merck & Co., told the Subcommittee on Oversight and Investigations of the House Committee on Energy and Commerce that healthcare cybersecurity still has a long way to go. “Cybersecurity in the healthcare industry is far worse than what is reported,” Rice stated. Despite the fact ...
- Internet-Connected Medical Washer-Disinfector Found Vulnerable to Hacking
March 27, 2017
Internet-of-Things devices are turning every industry into the computer industry, making customers think that their lives would be much easier with smart devices. There are, of course, some really good reasons to connect certain devices to the Internet. For example, remotely switching on your A/C a few minutes before you enter your home, instead of leaving ...

