Feeds

Conficker seizes city's hospital network

Network-wide update ban invites worm infection

High performance access to file storage

Exclusive Staff at hospitals across Sheffield are battling a major computer worm outbreak after managers turned off Windows security updates for all 8,000 PCs on the vital network, The Register has learned.

It's been confirmed that more than 800 computers have been infected with self-replicating Conficker code. Insiders at Sheffield Teaching Hospitals Trust said they suspect many more machines are affected but have not been reported to IT.

The Trust told The Register it now has the outbreak under control and is engaged in "clearing up" remnants. Non-urgent appointments in the medical imaging department had to be cancelled while its computers were disinfected. A Trust spokeswoman said no other direct impact on patient care was known.

The decision to disble automatic security updates was taken during Christmas week after PCs in an operating theatre rebooted mid-surgery. Conficker was detected on December 29.

David Whitham, the Trust's informatics director, said in a statement: "We do not know how the virus entered the network but at around the same time as the virus became evident the automatic update process had been temporarily disabled following problems with a number of PCs in theatres.

"This decision was taken by the IT Change Advisory Board to prevent further disruption in theatres which could have affected patient care." No individual was responsible for the move, the Trust added.

People close to the incident criticised the management decision to disable updates across the entire network rather than only where the reboots caused a problem. "Don't you just hate it when your boss is so computer illiterate yet has the power to veto the simplest of ideas to catastrophic end," said one, who asked to remain anonymous.

In internal emails seen by The Register, staff were warned not to make details of the outbreak public. "Please note that this incident could over the next few days attract outside interest from the press... If you are at any time approached by anyone to give information relating to the current problem then please refer them to me in the first instance," IT services manager Carol Hudson wrote.

A source said executives had not contacted Microsoft or other external security professionals for help eradicating Conficker, but the Trust disputed this. "Our IT team have been working very closely with external anti-virus specialists to remove the remnants from the network," Whitham said.

The trust argued that the consequences of its decision making had not cost public money, "just time and effort by the IT teams". It added: "A lot of lessons have been learned during the outbreak and they are being fully documented and discussed to prevent a repeat."

A Conficker outbreak is also currently affecting the Ministry of Defence. It's thought the worm acts to make infected machines vulnerable to further malware and harvests private information, though experts have warned its full purpose may not have been revealed yet.

Microsoft released a patch for the Conficker exploit in October, so updated machines should be unaffected. Until late December, Sheffield Teaching Hospitals Trust had a policy in place that would apply security updates across its network a few weeks after the patch release, and enforce a reboot.

Yesterday it was reported three in ten Windows PCs remain vulnerable to Conficker. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
HP ArcSight ESM solution helps Finansbank
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.