Feeds

Heartbleed implicated in US hospital megahack

This time superbug has nothing to do with MRSA

Secure remote control for conventional and virtual desktops

The Heartbleed flaw is responsible for the high-impact US hospital hacking attack disclosed this week, an unnamed investigator told Bloomberg.

As many as 4.5 million patient records have been exposed in an attack against Community Health Systems, a US hospital group that manages more than 200 hospitals.

China-based attackers stole millions of records which included data such as patient names, Social Security numbers, addresses, birth dates, and phone numbers after breaking into systems. No medical records nor any financial data was exposed by the nonetheless damaging breach, which CHS admitted had taken place between April and June as part of a regulatory filing.

A person "involved in the investigation who wasn’t authorised to comment publicly" blamed the Heartbleed OpenSSL bug for giving hackers a way into healthcare networks, an assessment backed up by a statement by a US security consultancy with a track record in accessing the IT security of government healthcare projects.

"The initial attack vector was through the infamous OpenSSL 'Heartbleed' vulnerability which led to the compromise of the information," according to security consultancy TrustedSec, which was the first to comment on the reported cause of the breach.

"This confirmation of the initial attack vector was obtained from a trusted and anonymous source close to the CHS investigation. Attackers were able to glean user credentials from memory on a CHS Juniper device via the Heartbleed vulnerability (which was vulnerable at the time) and use them to login via a VPN," it added.

"From here, the attackers were able to further their access into CHS by working their way through the network until the estimated 4.5 million patient records were obtained from a database," it said.

David Kennedy, TrustedSec's founder and principal consultant, worked at the National Security Agency and the United States Marines in cyber warfare and forensics analysis prior to moving into the private sector. Last November, he testified before Congress on the security shortcomings of HealthCare.gov. So while not directly involved, TrustedSec is a credible commentator on healthcare-related security issues and Kennedy seems connected enough to get the early drop on problems in this area.

Community Health Systems has reportedly hired Mandiant to handle the security response and cleanup necessary in the wake of the breach.

The Heartbleed security bug, first publicly disclosed in early April, stems from a buffer overflow vulnerability in the Heartbeat component of OpenSSL. The vulnerability meant all manner of sensitive data – including encryption keys, bits of traffic, credentials or session keys – might be extracted from unpatched systems.

Previous victims of Heartbleed include Canada's tax agency, UK parenting website Mumsnet and the developers of Call of Duty: Black Ops II. The practical consequence of these breaches involved nothing more serious than a precautionary password reset for Mumsnet's 1.5 million customers. The reported breach against Community Health Systems is far more serious than anything previously recorded. ®

Beginner's guide to SSL certificates

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Go beyond APM with real-time IT operations analytics
How IT operations teams can harness the wealth of wire data already flowing through their environment for real-time operational intelligence.
The total economic impact of Druva inSync
Examining the ROI enterprises may realize by implementing inSync, as they look to improve backup and recovery of endpoint data in a cost-effective manner.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.