Virginia Health Database Held For Ransom
An anonymous reader writes "The Washington Post's Security Fix is reporting that hackers broke into servers at the Virginia health department that monitors prescription drug abuse and replaced the homepage with a ransom demand. The attackers claimed they had deleted the backups, and demanded $10 million for the return of prescription data on more than 8 million Virginians. Virginia isn't saying much about the attacks at the moment, except to acknowledge that they've involved the FBI, and that they've shut down e-mail and a whole mess of servers for the state department of health professionals. The Post piece credits Wikileaks as the source, which has a copy of the ransom note left behind by the attackers."
The phrasing "gone missing" makes him sound like he's from somewhere in the United Kingdom...
Yes, but the phrase "Now I hear tell" indicates Virginia! What a conundrum! This case will never be cracked! The full note text for those too lazy to click through wikileaks:
ATTENTION VIRGINIA
:(
;)
I have your shit! In *my* possession, right now, are 8,257,378 patient records and a total of 35,548,087 prescriptions. Also, I made an encrypted backup and deleted the original. Unfortunately for Virginia, their backups seem to have gone missing, too. Uhoh
For $10 million, I will gladly send along the password. You have 7 days to decide. If by the end of 7 days, you decide not to pony up, I'll go ahead and put this baby out on the market and accept the highest bid. Now I don't know what all this shit is worth or who would pay for it, but I'm bettin' someone will. Hell, if I can't move the prescription data at the very least I can find a buyer for the personal data (name,age,address,social security #, driver's license #).
Now I hear tell the Fucking Bunch of Idiots ain't fond of payin out, but I suggest that policy be turned right the fuck around. When you boys get your act together, drop me a line at hackingforprofit@yahoo.com and we can discuss the details such as account number, etc.
Until then, have a wonderful day, I know I will
My work here is dung.
The state of Michigan had this same scenario play out two years ago. The only difference: it was part of one of their Cyberstorm security exercises. At a round table discussion, the acting IT infrastructure director talked about how the exercise opened. He sat down at his desk one day, opened his e-mail, and found a ransom note that mirrors exactly what's going on now in Virgina.
It gets better. Certain key members of the IT infrastructure were given instructions ahead of time to take the day off, not tell anyone they were told to take the day off and, best of all, not answer their phone or e-mail unless they were being contacted by a specific person. (Someone who was 'in' on the exercise, and who had the authority to say "ah crap, XYZ is down and it's not part of the exercise, call Bob and let him know we actually need him.")
All in all it was an interesting discussion of "what if?" that I'd love to try out in my own workplace. Sure, if someone's on call and doesn't answer their phone, you beat them with at bamboo cane a the next opportunity. But what do you do in the meantime? If crap hits the fan, do your managers & team leads really know their call flows? Or does everyone just freak out and call the guy that usually knows what he's doing? What happens when that guy gets hit by a bus?
There are some people that if they don't know, you can't tell 'em.
No doubt a reference to the FBI.
HTTP/1.1 200 OK
Server: Microsoft-IIS/5.0
MicrosoftOfficeWebServer: 5.0_Pub
PICS-Label: (PICS-1.0 "http://www.rsac.org/ratingsv01.html" l on "2002.01.30T11:07-0400" exp "2035.12.31T12:00-0400" r (v 0 s 0 n 0 l 0))
Connection: keep-alive
Content-Location: http://www.dhp.virginia.gov/Default.htm
Date: Tue, 05 May 2009 13:22:56 GMT
Content-Type: text/html
Accept-Ranges: bytes
Last-Modified: Fri, 01 May 2009 20:54:08 GMT
ETag: "0d886f89ecac91:af5"
Content-Length: 18149
Even if it was 10GBs worth of data, once an attacker can sneak into the system, it's possible to download it all without getting noticed... If the server has a fat pipe, it's likely nobody will notice a minor amount of additional overhead. However, there remains the question of how the attacker could know that there are no additional backups.
There have been ransom cases like this before, dating as far back as the 80s I believe (perhaps even the 70s), where it was an inside job, and the attackers stole all the physical backup media. It's possible the attackers worked there, and thought they could get enough money this way to "disappear". This seems stupid to me, however. There just doesn't seem to be a way for them to get those 10 millions without being traced.
Nope.
and here's somethign that will scare you.
MOST Companies don't know what iron mountain is and what tape drives are for. a bulk of companies and corporations have incredible jokes they call their backup system/policy.
They spend more on the CEO's toilet than they do on data security and integrity.
Do not look at laser with remaining good eye.
have you?
I've been working for contractors for 10 years now, and am still surprised by the level of incompetence that some government IT folks demonstrate.
Some are good. NOAA OMAO really has its stuff together. DoJ? Not so much..
Best Slashdot Co
Silvadene is avail in a generic. Yes it requires an Rx but you can get 50gm for near $10, nowhere near $80.
/Pharmacist
It's true. Where I work, we have very good security. This is because we have very good security engineers who select (or write) the tools they use, rather than having some shitty pie-chart generating security app shoved on us by some middle manager who liked the sales presentation.
Infosec really is an art at this point. Managers, don't tell the artist what equipment he can use. Your $40,000 SIM is going to be completely wasted, because syslog + a perl script will get him exactly what he needs in exactly the format he wants in less time than it takes to open the box on the SIM.
A slashdotter who didn't build his own computer is like a Jedi who didn't build his own lightsaber.
I don't know of anywhere where you need a licence to develop software.
Using a PC doesn't require a licence, but the troll included it in the list in an attempt to prove his point.
Watching TV, however, does require a licence in a number of countries.
"City hall" in German is "Rathaus" Kinda explains a few things......
Just for clarification, the Virginia Department of Health Professionals is not the same agency as the Virginia Department of Health.
Each Virginia agency is its own little independent IT fiefdom, with all the disparity of budget and clue that entails. At least until their IT is taken over by Northrop Grumman, which is another clusterfuck entirely...
It's a reference to the Sherlock Holmes story "The Bohemian Scandal", wherein, Holmes explains to Watson that the note that he (Holmes) has received was written by a German, based on the sentence structure.
Mr. Hu is not a ninja.