Transcription of Lessons Learned from the HSE Cyber Attack
1 LEADERSHIP FOR IT SECURITY & PRIVACY ACROSS HHS HHS CYBERSECURITY PROGRAM OFFICE OF INFORMATION SECURITYL essons Learned from the HSE Cyber Attack02/03/2022 TLP: WHITE, ID# 202202031300 Agenda2 Background on the HSE Cyber Attack Threat Profile for Conti Ransomware HC3 Observations for Conti Ransomware Timeline of the Incident Key Findings General Takeaways for Healthcare OrganizationsNon-Technical:Managerial, strategic and high-level (general audience)Technical:Tactical / IOCs; requiring in-depth knowledge (sysadmins, IRT)Slides Key: 3 The Health Service Executive (HSE) of Ireland is thecountry s publicly funded healthcare system under the IrishDepartment of Health, consisting of 54 public hospitalsdirectly under HSE authority, and voluntary hospitals whichutilize national IT infrastructure. On May 14, 2021, HSE suffered a major ransomwarecyberattack that caused all its IT systems nationwide to beshut down. It became the most significant cyberattack on an Irish stateagency, as well as the largest known Attack against a healthservice computer system in history, occurring during theCOVID-19 pandemic.
2 It took four months to completely recover from the Attack ,with HSE sustaining numerous impacts to healthcaredelivery during this timeframe (discussed in the next slide). Conti ransomware was responsible for the incident. On December 3, 2021, HSE published an Independent PostIncident Review consisting of a 157-page redacted report,which is the foundation of this brief. Full report of the Conti Cyber Attack on the HSE: on the HSE Cyber Attack 4 Hospital staff were forced to revert to pen andpaper 80% of the HSE IT environment was encrypted,severely disrupting healthcare servicesthroughout the country Prevented access to diagnostics and medicalrecords Exposed the private information of thousandswho received the COVID-19 vaccine National vaccination program was notaffected Exfiltrated 700 GB of unencrypted data includingprotected health information (PHI) Specialists tracked stolen HSE data to acommercial server in the Lawsuits from patients over interrupted patientcare Large financial cost to respond to the incident And Profile Impacts of the HSE Cyber Attack 5 Malware First Surfaced: December 2019 Suspected Predecessor(s): Ryuk Malware Capabilities: Ransomware written in C/C++ that mainly encrypts local files Targeted Systems.
3 All versions of Windows known to be affected Associated Malware/Tools: TrickBot, IcedID, Cobalt strike , BazarLoader, Zloader,Rclone, LaZagne, Sidoh, etc. Infection Vectors: Spear phishing; Remote Desktop Protocol (RDP); phone calls; fakesoftware; other malware; common vulnerabilities in external assets ( , Log4j)Group Origin: Eastern Europe, Russian Federation Industry Names: Wizard Spider Associated Actors: UNC1878, , Grim Spider, UNC2633, UNC2727 Forum Presence: Public and Private Forums Targeted Countries: United States, France, Germany, Canada, UK, Italy, Australia, Spain,Netherlands Targeted Industries: Manufacturing, construction, retail, legal, financial, technology,automotive, hospitality, transportation, energy, healthcare Status: Conti became the first professional-grade, sophisticated ransomware group toweaponize Log4j2 with a full Attack chain in December 2021 Classification: Highly-sophisticated, financially-motivated cybercriminal ransomware-as-a-service (RaaS) program.
4 Human-operated Threat to HPH Sector: Elevated RiskCyber Threat Profile: Conti Ransomware 6 HC3 tracked at least 40ransomware incidents involvingConti ransomware in 2021 Targeted countries within thehealthcare industry includedAustralia, Colombia, France,Germany, India, Italy,Netherlands, the United Kingdom,and the United States HPH entities in at least 20 experienced Contiransomware incidents orappeared on the Contiransomware extortion blog Sub-industries within healthcareimpacted included Biotechnology,Health or Medical Clinic,Healthcare Industry Services,Home Health Care Services,Hospice or Elderly Care, Hospital,Pharmaceutical Industry, andPublic Health entitiesHistorical Conti Ransomware Incidents in the HPH Sector Worldwide (2021)Biotechnology5%Health or Medical Clinic32%Healthcare Industry Services29%Home Healthcare or Elderly Care Services10%Hospital5%Pharmaceutical Industry14%Public Health5%Industry Breakdown.
5 Conti Ransomware Incidents (2021) 7 Pre-Infection Timeline: March 18 May 14, 2021 Source: HSE/PwC8 Post-Infection Timeline: May 14 September 21, 2021 Source: HSE/PwC9 The HSE did not have a single responsible owner for cybersecurity, at senior executive or managementlevel at the time of the incident. There was no dedicated committee that provided direction and oversight of cybersecurity and the activitiesrequired to reduce the HSE's Cyber risk exposure. There were known weaknesses and gaps in key cybersecurity controls. The lack of a cybersecurity forum in the HSE hindered the discussion and documentation of granular cyberrisks, as well as the abilities to identify and deliver mitigating controls. The HSE did not have a centralized cybersecurity function that managed cybersecurity risk and controls. It was a known issue that the teams with cybersecurity responsibilities were Findings: Ransomware Attack Preparedness 10 The HSE s technology has grown organically and isconsequently overly complex, increasing thevulnerability of the HSE to Cyber attacks.
6 The HSE had a large and unclear security boundary thatencompassed many of the organizations connected tothe National Healthcare Network (NHN). The HSE s effective security boundary did not align withits ability to mandate cybersecurity controls. There was no effective security monitoring capability thatwas able to detect, investigate and respond to securityalerts across the HSE's IT environment. The antivirus tool was over-relied upon to detect andprevent threats on endpoints. The IT environment had high-risk gaps relating to 25 outof 28 of the cybersecurity controls that are most effectiveat detecting and preventing human-operatedransomware attacks. The HSE did not have a documented Cyber incidentresponse plan and had not performed typical preparatoryactivities, such as exercising the technical Findings: Ransomware Attack Preparedness (cont.) 11 The Cyber Attack was not actively identified nor contained prior tothe ransomware execution, despite the attacker performing noisyand unstealthy actions.
7 The HSE s antivirus identified a tool commonly used byransomware groups (Cobalt strike ) on six servers on May 7, 2021(and several more servers in the following days) but these alertswere not appropriately actioned. Two voluntary hospitals identified suspicious activity prior to theexecution of ransomware, but a HSE centralized response wasnot initiated. Two organizations successfully acted on detections of theattacker, preventing the deployment of ransomware within theirestates. The HSE, with the help of third parties, mobilized a response tothe ransomware Attack and overcame many of the significantchallenges the ransomware Attack presented, drawing on theirexperience responding to crises including COVID-19. The HSE was reliant on third parties in the early weeks of theincident to provide structure to the response activities. Time was lost during the response due to a lack of pre-planningfor high impact technology Findings: Ransomware Attack Response 12 The HSE spent a significant amount of time during the responsegathering information about applications, as this information was notrecorded and up-to-date in a central or offline application register.
8 There was a heavy reliance on specific individuals during theresponse. This likely contributed to a recovery timeline that waslonger than could have been achieved. The response initially prioritized the recovery of foundationalsystems, and applications on the operators of essential services list,before advancing to an approach that focused on clinical risks andthe recovery of end-to-end clinical services. There was a lack of clearly defined and delineated decision-makingauthority between the HSE, hospitals and Community HealthcareOrganizations (CHO) in the case of a health service-wide crisis. The OCIO was not able to provide or source (through third partyburst capacity) the scale of the IT support required by hospitals andCHOs during the extended response to restore applications, systemsand services at pace. The HSE had limited to no ability to investigate the Attack using itsown tooling. The HSE s Incident Response provider identified evidence of howthe attacker was able to gain unauthorized access to the HSE s ITenvironment, as well as the attacker s subsequent Findings: Ransomware Attack Response (cont.)
9 13 The impact of the ransomware on the ITenvironment was reported by the HSE smanagement to lead to 80% encryption. The impact of the ransomware Attack oncommunications was severe, as the HSE almostexclusively used on-premise email systems(including Exchange) that were encrypted, andtherefore unavailable, during the Attack . The HSE took action to contain the ransomwareattack by powering down systems anddisconnecting the NHN from the internet. It is unclear how much data would have been lost ifa decryption key had not become available. Without the decryption key, it is unknown how longit would have taken to recover systems frombackups, but it would have likely takenconsiderably longer. The HSE missed opportunities for efficiencies inthe recovery of systems and applications due to alack of Findings: Ransomware Attack Impact and Recovery 14 Governance and cybersecurity of technology dependency andgovernance of technology strategy and cybersecurity monitoring and of cybersecurity capability throughsimulated attacksPreparedness to respond and incident response andcrisis management continuity planning and IT disasterrecovery planning for a ransomware incident and crisis supportGeneral Takeaways for Healthcare Organizations Reference Materials16 Abrams, Lawrence.
10 2021. Conti ransomware gives HSE Ireland free decryptor, still selling January 26, 2022.. 2021. Irish High Court issues injunction to prevent HSE data 20. Accessed January 26, Aodha, Gr inne N . 2021. HSE shuts down IT systems after 'major' ransomware Attack , vaccination rolloutnot 14. Accessed January 26, 2022. systems-after-major-ransomware- Attack -va ccination-rollout-not-affected/ar-BB1gIE Tg BBC News. 2021. Cyber Attack 'most significant on Irish state'.May 14. Accessed January 26, Bowers, Sean O'Rioran and Shauna. 2021. Cancer patient to sue Cork's Mercy Hospital over Cyber hack .July 15. Accessed January 26, 2022. 2021. Cork hospital had help from Defence Forces after HSE January 26, 202. Ciara O'Brien, Simon Carswell. 2021. Coombe hospital services continuing as normal after 16. Accessed January 26, 2022. CISA. 2021. Alert (AA21-265A) - Conti 22. Accessed January 26, 17 Coble, Sarah.