Hospital pays despite having backups
I try never to second guess an organizations decision when faced with a security or disaster challenge. That being said, I believe the less these bad actors get paid the less likely they are to do ransom attacks.
Image from the Greenfield Reporter
http://www.greenfieldreporter.com/2018/01/16/01162018dr_hancock_health_pays_ransom/
Here is a story about a hospital that paid even with backups. The reason given is a valid concern for many organizations. If you get large enough, the backups can take days to complete. That is something that needs to be taken in to consideration when creating a threat profile and response matrix. While they don't say how it happens, the SamSam that was used normally travels by RDP.
Bleeping has a right up on the issue here:
https://www.bleepingcomputer.com/news/security/hospital-pays-55k-ransomware-demand-despite-having-backups/
Comments
Post a Comment