Transcription of Lessons Learned from the HSE Cyber Attack
{{id}} {{{paragraph}}}
LEADERSHIP FOR IT SECURITY & PRIVACY ACROSS HHS HHS CYBERSECURITY PROGRAM OFFICE OF INFORMATION SECURITYL essons Learned from the HSE Cyber Attack02/03/2022 TLP: WHITE, ID# 202202031300 Agenda2 Background on the HSE Cyber Attack Threat Profile for Conti Ransomware HC3 Observations for Conti Ransomware Timeline of the Incident Key Findings General Takeaways for Healthcare OrganizationsNon-Technical:Managerial, strategic and high-level (general audience)Technical:Tactical / IOCs; requiring in-depth knowledge (sysadmins, IRT)Slides Key: 3 The Health Service Executive (HSE) of Ireland is thecountry s publicly funded healthcare system under the IrishDepartment of Health, consisting of 54 public hospitalsdirectly under HSE authority, and voluntary hospitals whichutilize national IT infrastructure. On May 14, 2021, HSE suffered a major ransomwarecyberattack that caused all its IT systems nationwide to beshut down. It became the most significant cyberattack on an Irish stateagency, as well as the largest known Attack against a healthservice computer system in history, occurring during theCOVID-19 pandemic.
ransomware groups (Cobalt Strike) on six servers on May 7, 2021 (and several more servers in the following days) but these alerts were not appropriately actioned. • Two voluntary hospitals identified suspicious activity prior to the execution of ransomware, but a HSE centralized response was not initiated.
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}