UK data watchdog fines NHS vendor Advanced for security failures prior to LockBit ransomware attack

Date:

Share post:


U.K. data protection authorities have issued a provisional fine of more than £6 million to NHS vendor Advanced after finding that the company failed to properly secure the information of thousands of people later stolen in a ransomware attack.

In a statement, the U.K. Information Commissioner’s office (ICO) said it issued the fine after determining that the cybercriminals behind the August 2022 ransomware attack “initially accessed a number of Advanced’s health and care systems via a customer account that did not have multi-factor authentication.”

The cyberattack on Advanced led to widespread disruption to NHS services across the United Kingdom at the time, causing outages at the NHS non-emergency 111 line and forcing hospitals and medical practices to resort to pen and paper for weeks. Physicians at affected NHS trusts reported that they could not access patient records.

Mandiant, the incident response firm that helped to investigate the hack, said malware used by the LockBit ransomware gang was used in the attack; though, LockBit never publicly claimed responsibility for the cyberattack on its dark web leak site. That can be an indication that a hacked company may have paid a ransom. Advanced previously declined to say if it had paid one.

By October 2022, Advanced said in its post-incident report that the cybercriminals broke into Advanced’s network “using legitimate third-party credentials,” implying that there was no multi-factor authentication on the account. 

Now the ICO appears to be confirming that.

The ICO said it’s provisionally issuing a fine of £6.09 million ($7.75 million) after the watchdog said Advanced provisionally “breached data protection law in failing to implement appropriate security measures prior to the attack to protect the personal information it was processing.”

The watchdog also confirmed that the cyberattack led to the theft of data of close to 83,000 people in the United Kingdom, including phone numbers and medical records, and details of “how to gain entry to the homes of 890 people who were receiving care at home,” the ICO said.

The fine is provisional, the watchdog said, meaning the penalty may change. ICO Commissioner John Edwards said the watchdog made the decision to go public in this case in part to “avoid similar incidents in the future.”

“I urge all organisations, especially those handling sensitive health data, to urgently secure external connections with multi-factor authentication,” said Edwards.

Spokespeople for Advanced did not respond to a request for comment prior to publication.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

Amazon’s telehealth platform adds low-cost plans for hair loss, skin care, and more

Amazon One Medical is expanding its telehealth services with the launch of upfront and low-cost treatment plans...

Sales tax automation startup Kintsugi doubled its valuation this year

A 2018 Supreme Court ruling eliminated the requirement that an e-commerce retailer needed a physical location in...

Snapchat will soon be able to alert parents when their teen leaves or arrives at certain locations

Snapchat is bringing enhanced location sharing to Family Center, its parental controls hub, the company announced Thursday. Users...

PayPal once again lets you pool money from others to pay for things together

PayPal is launching a few features that let users in groups pool money with friends or family,...

US confirms China-backed hackers breached telecom providers to steal wiretap data

The U.S. government has confirmed that hackers with links to China breached multiple U.S. telecommunication service providers...

Tessl raises $125M at at $500M+ valuation to build AI that writes and maintains code

Many startups and larger tech companies have taken a crack at building artificial intelligence to code software....

Atlas.co wants its web-based mapping tool to be the Figma of geospatial data

Startup inspiration can strike anywhere. But for Atlas.co*, a freemium browser-based, real-time mapping tool that’s being built...

ePlane looks to ride the Indian government’s interest in air taxis with new $14M round

Soaring private vehicle ownership and declining use of public and non-motorized transport have created mounting traffic congestion...