Indian Healthcare faced enormous cyber attacks in 2022, Till

Indian Healthcare faced enormous cyber attacks in 2022, Till Nov: CyberPeace Foundation and Autobot Infosec Report

New Delhi [India], November 30 (ANI/NewsVoir): Cyber attacks on healthcare facilities have been rising in recent years, and the pandemic has only worsened matters. With hospitals and other healthcare facilities struggling to keep up with the demand for care, they have become an easy target for cybercriminals. While this may seem like a small amount, it can be devastating for a hospital that is already stretched thin. Research done by CyberPeace Foundation (CPF), Autobot Infosec Private Limited, along with the academic partners under CyberPeace Center of Excellence (CCoE), has found that nearly 1.9 million attack events have been recorded in 2022 till 28th November on the Healthcare based threat intelligence sensors network simulated by the research group in India. The study is a part of CyberPeace Foundation's e-Kawach program to implement comprehensive public network and threat intelligence sensors across the country to capture internet traffic and analyze real-time cyberattacks that a location or an organization faces. A credible intelligence on real-time threats empowers organizations or a Country to build cybersecurity policies. "By deploying the simulated network, we can collect data on attack patterns, the different types of attack vector for the different protocols, and the recent trends of malicious activity," - Spokesperson, CyberPeace Foundation added. Trends noticed by the Research Like any other critical infrastructure worldwide, the Indian Healthcare infrastructure is also vulnerable to cyber attacks involving state & non-state actors. The Healthcare based threat intelligence sensors network deployed by the CyberPeace Foundation, Autobot Infosec Private Ltd. with the CyberPeace Center of Excellence (CCoE) partners has seen a surge in the number of cyberattacks with 1846712 hits between January 2022 to November 28th 2022 from a total number of 41181 Unique IP addresses appearing from countries like Vietnam, Pakistan, China etc. The vulnerable internet-facing systems having Remote Desktop Protocol (RDP), vulnerable SMB and Database services enabled, and old Windows server Platforms were mostly attacked. Attackers also tried to inject malicious payloads into the network. The deployed network has captured a total of 1527 unique payloads belonging to Trojan, Ransomware, etc. Analysis of data has drawn the attention that attackers also tried to exploit DICOM/MYSQL/MSSQL protocols to access the sensitive patients data like medical images, diagnostic databases etc. DICOM is standard protocol used in most medical and healthcare facilities for the management and transmission of medical images and related data. Research team noticed a massive brute force, dictionary attacks were performed against the protocols FTP, MYSQL and MSSQL using some common credentials like 'root', 'ftp', 'admin', 'web', 'web!', 'qwerty', 'password1', 'sql2005', 'passw0rd', 'administrator' etc. One new trend has been noticed that attackers are nowadays using long passwords, not usually mentioned in the English dictionary, for example '4yqbm4,m`~!@~#$%^&*(),.;' and '!@#$%^&*'. Some common FTP commands were also captured - "USER", "PASS", "PWD", "CWD", "PASV", "STOR", "PASV", "STOR", "PASV", "STOR", "PASV", "STOR", "PASV", "STOR", "PASV", "STOR", "TYPE". In an earlier report released in August 2022, CyberPeace of Foundation also mentioned that there has been an increase in the number of phishing/social engineering attacks on Indian organizations in the Healthcare business. CPF spokesperson drew attention to WhatsApp messages masquerading as an offer from Apollo Hospital with links luring unsuspecting users with the promise of medical subsidy presents making the rounds on the app. Recently, news has been making the rounds on the internet that All India Institute of Medical Sciences (AIIMS), Delhi faced a Cyberattack probably with the injected Ransomware on their systems. "Cyber criminals are taking advantage of the fact that healthcare organizations are under immense strain and are more likely to pay a ransom to get their systems up and running again. Organisations should ensure their systems are secured by reducing unnecessary data, improving the patch level of software, backup and restore procedures and auditing systems to build awareness of any threats," - Spokesperson added. The Advisory - Do not expose critical services unnecessarily to the internet. - Network firewalls should always be patched with the latest security updates. - Isolate the critical network from the public network. - Periodically perform technical audits of Healthcare Infrastructure Devices, networks and any other end-points directly or indirectly connected to it, to identify security concerns. - Run CyberAwareness Drive by Cyber Experts at regular intervals for the team. - Develop an R&D lab to enhance CyberSecurity skills among the employees. - Maintain strong Password Policy: - Use a strong password for all devices and online accounts. - Passwords should be at least 8-13 characters long. - Passwords should contain at least one upper case (A-Z), numeric character (0-9), and a special character (!@%&....). - Where possible it is recommended to use key based authentication along with passwords. - Do not use the same password for all your online accounts. All the passwords should be different for different versions. - Try avoiding a password that consists of dictionary words. - Stay away from Phishing links: Phishing is an attempt of social engineering techniques to inject malware or obtain sensitive information such as usernames, passwords, and credit card information by spreading fake links and pretending to be acting as a trustworthy entity. Please do not click on such links before verifying the authenticity of the same. - Never share or forward fake messages containing links to any social platform without proper verification. For more details, reach out to us at secretariat@cyberpeace.net. This story has been provided by NewsVoir. ANI will not be responsible in any way for the content of this article. (ANI/NewsVoir)

Related Keywords

China , Vietnam , Republic Of , Delhi , India , Pakistan , New Delhi , , Cyberpeace Center , Autobot Infosec Private , Cyberpeace Of Foundation , Cyberpeace Foundation , India Institute Of Medical Sciences , Autobot Infosec Private Ltd , Autobot Infosec Private Limited , Indian Healthcare , Remote Desktop Protocol , Apollo Hospital , All India Institute , Medical Sciences , Healthcare Infrastructure Devices , Cyberawareness Drive , Cyber Experts , Password Policy , New Delhi India , Ovember 30 Ani Newsvoir Cyber Attacks On Healthcare Facilities Have Been Rising In Recent Years , Nd The Pandemic Has Only Worsened Matters With Hospitals And Other Healthcare Facilities Struggling To Keep Up Demand For Care , Hey Have Become An Easy Target For Cybercriminals While This May Seem Likea Small Amount , T Can Be Devastating Fora Hospital That Is Already Stretched Thin Research Done By Cyberpeace Foundation Cpf , Long With The Academic Partners Under Cyberpeace Center Of Excellence Ccoe , As Found That Nearly 1 9 Million Attack Events Have Been Recorded In 2022 Till 28th November On The Healthcare Based Threat Intelligence Sensors Network Simulated By Research Group India Study Isa Part Of Cyberpeace Foundation 39 Se Kawach Program To Implement Comprehensive Public And Across Country Capture Internet Traffic Analyze Real Time Cyberattacks Thata Location Or An Organization Facesa Credible Threats Empowers Organizations Ora Build Cybersecurity Policies Quot Deploying , E Can Collect Data On Attack Patterns , He Different Types Of Attack Vector For The Protocols , Nd The Recent Trends Of Malicious Activity , Uot Spokesperson , Yberpeace Foundation Added Trends Noticed By The Research Like Any Other Critical Infrastructure Worldwide , He Indian Healthcare Infrastructure Is Also Vulnerable To Cyber Attacks Involving State Amp Non Actors The Based Threat Intelligence Sensors Network Deployed By Cyberpeace Foundation , Utobot Infosec Private Ltd With The Cyberpeace Center Of Excellence Ccoe Partners Has Seena Surge In Number Cyberattacks 1846712 Hits Between January 2022 To November 28th Froma Total 41181 Unique Ip Addresses Appearing From Countries Like Vietnam , Hina Etc The Vulnerable Internet Facing Systems Having Remote Desktop Protocol Rdp , Ulnerable Smb And Database Services Enabled , Nd Old Windows Server Platforms Were Mostly Attacked Attackers Also Tried To Inject Malicious Payloads Into The Network Deployed Has Captureda Total Of 1527 Unique Belonging Trojan , Ransomware , Tc Analysis Of Data Has Drawn The Attention That Attackers Also Tried To Exploit Dicom Mysql Mssql Protocols Access Sensitive Patients Like Medical Images , Iagnostic Databases Etc Dicom Is Standard Protocol Used In Most Medical And Healthcare Facilities For The Management Transmission Of Images Related Data Research Team Noticeda Massive Brute Force , Ictionary Attacks Were Performed Against The Protocols Ftp , Ysql And Mssql Using Some Common Credentials Like 39 Root , 9 Ftp 39 , 9 Admin 39 , 9 Web 39 , 9 Qwerty 39 , 9 Password1 39 , 9 Sql2005 39 , 9 Passw0rd 39 , 9 Administrator 39 Etc One New Trend Has Been Noticed That Attackers Are Nowadays Using Long Passwords , Ot Usually Mentioned In The English Dictionary , Or Example 39 4yqbm4 , Pam Amp , 9 And 39 Amp Some Common Ftp Commands Were Also Captured Quot User , Uot Pass Quot , Uot Pwd Quot , Uot Cwd Quot , Uot Pasv Quot , Uot Stor Quot , Uot Type Quot In An Earlier Report Released August 2022 , Yberpeace Of Foundation Also Mentioned That There Has Been An Increase In The Number Phishing Social Engineering Attacks On Indian Organizations Healthcare Business Cpf Spokesperson Drew Attention To Whatsapp Messages Masquerading As Offer From Apollo Hospital With Links Luring Unsuspecting Users Promise Medical Subsidy Presents Making Rounds App Recently , Ews Has Been Making The Rounds On Internet That All India Institute Of Medical Sciences Aiims , Elhi Faceda Cyberattack Probably With The Injected Ransomware On Their Systems Quot Cyber Criminals Are Taking Advantage Of Fact That Healthcare Organizations Under Immense Strain And More Likely To Paya Ransom Get Up Running Again Organisations Should Ensure Secured By Reducing Unnecessary Data , Mproving The Patch Level Of Software , Ackup And Restore Procedures Auditing Systems To Build Awareness Of Any Threats , Uot Spokesperson Added The Advisory Do Not Expose Critical Services Unnecessarily To Internet Network Firewalls Should Always Be Patched With Latest Security Updates Isolate From Public Periodically Perform Technical Audits Of Healthcare Infrastructure Devices , Etworks And Any Other End Points Directly Or Indirectly Connected To It , O Identify Security Concerns Run Cyberawareness Drive By Cyber Experts At Regular Intervals For The Team Develop Anr Ampd Lab To Enhance Cybersecurity Skills Among Employees Maintain Strong Password Policy Usea All Devices And Online Accounts Passwords Should Be Least 8 13 Characters Long Contain One Upper Caseaz , Umeric Character 0 9 , Nda Special Character Amp Where Possible It Is Recommended To Use Key Based Authentication Along With Passwords Do Not The Same Password For All Your Online Accounts Should Be Different Versions Try Avoidinga That Consists Of Dictionary Words Stay Away From Phishing Links An Attempt Social Engineering Techniques Inject Malware Or Obtain Sensitive Information Such As Usernames , Passwords , Nd Credit Card Information By Spreading Fake Links And Pretending To Be Acting Asa Trustworthy Entity Please Do Not Click On Such Before Verifying The Authenticity Of Same Never Share Or Forward Messages Containing Any Social Platform Without Proper Verification For More Details , Each Out To Us At Secretariat Cyberpeace Net This Story Has Been Provided By Newsvoir Ani Will Not Be Responsible In Any Way For The Content Of Article ,

© 2025 Vimarsana