Feeds

Hackers demand $10m ransom for Virginia medical data

8.3 million records held hostage

The essential guide to IT transformation

Almost 8.3 million patient records have been stolen from a Virginia government website that tracks prescription drug abuse, according to hackers who are demanding a $10 million ransom for their return.

"I have your shit!" the note, which was posted to Wikileaks read. "In *my* possession, right now, are 8,257,378 patient records and a total of 35,548,087 prescriptions. Also, I made an encrypted backup and deleted the original. Unfortunately for Virginia, their backups seem to have gone missing, too."

The message said if officials didn't respond within seven days the information would be made available to whoever offered the highest bid. The story was first reported by Brian Krebs's Security Fix blog.

The claims could not immediately be verified. It stretches the imagination to believe outsiders could break into a state-run website and destroy both the original data and its backup, which presumably would be stored off-site. A spokeswoman from Virginia's Department of Health Professions didn't return a phone call seeking comment. She told Security Fix the website was shut following following the April 30 discovery of an intrusion. She never directly addressed whether sensitive data was stolen or deleted.

The Virginia PMP homepage remained unreachable at time of writing, and the state has temporarily discontinued email to and from the department, Security Fix said. An FBI spokesman in Richmond, Virginia told the Associated Press the agency was investigating a referral from the Virginia Information Technologies Agency. State police said they are assisting as well, the AP reported.

The episode is the latest cautionary tale to involve the mass storage of medical records in electronic form. When not secured properly, these are easier to steal than paper records. In November, pharmacy prescription processor Express Scripts offered a $1m bounty for information leading to the arrest of blackmailers who threatened to disclose stolen records belonging to millions of patients.

President Barack Obama has made the digitization of medical records a major pillar of his push to lower the cost of health care. Assuming the extortionists in this case aren't bluffing when they say they've acquired records belonging to almost 8.3 million people, electronic storage of such sensitive information comes with a cost that can be underestimated only at our peril. ®

5 things you didn’t know about cloud backup

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
KER-CHING! CryptoWall ransomware scam rakes in $1 MEEELLION
Anatomy of the net's most destructive ransomware threat
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
prev story

Whitepapers

Gartner critical capabilities for enterprise endpoint backup
Learn why inSync received the highest overall rating from Druva and is the top choice for the mobile workforce.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.