Slashdot Mirror


Virginia Health Database Held For Ransom

An anonymous reader writes "The Washington Post's Security Fix is reporting that hackers broke into servers at the Virginia health department that monitors prescription drug abuse and replaced the homepage with a ransom demand. The attackers claimed they had deleted the backups, and demanded $10 million for the return of prescription data on more than 8 million Virginians. Virginia isn't saying much about the attacks at the moment, except to acknowledge that they've involved the FBI, and that they've shut down e-mail and a whole mess of servers for the state department of health professionals. The Post piece credits Wikileaks as the source, which has a copy of the ransom note left behind by the attackers."

26 of 325 comments (clear)

  1. Non-story? by Jane_Dozey · · Score: 5, Insightful

    I'm assuming that not even a governmental department can be stupid enough not to have copies of the backups in a fire safe, off-site location.

    --
    Silly rabbit
    1. Re:Non-story? by cayenne8 · · Score: 4, Insightful
      Even if that weren't the case.

      Sure should put a damper on people wanting a national central medical record database.

      Well, it would for reasonable people, but, that has nothing to do with politicians and agendas.

      --
      Light travels faster than sound. This is why some people appear bright until you hear them speak.........
    2. Re:Non-story? by Curunir_wolf · · Score: 3, Insightful

      They don't need that data anyway. The only thing it's used for is to inform the DEA of people that might be abusing prescription drugs (yea, like Limbaugh). So, good riddance.

      The real issue is that the state (and all the others, BTW) is collecting all this personal information on their citizens and storing it in a database that is vulnerable to attack by identity thieves. It's one of the problems with all of these "citizen tracking" systems (like, for instance, Real ID). It's an unnecessary government intrusion that collects personal information for tracking its citizens, and providing them the ability to use citizens' own information against them. The excuse is always for "security". Well, you see now how good the government is at security.

      Just wait until they have all your health records in an electronic health record database. It'll be available to everyone, everywhere. Authorized personnel only, of course. Yea, right.

      --
      "Somebody has to do something. It's just incredibly pathetic it has to be us."
      --- Jerry Garcia
    3. Re:Non-story? by dpilot · · Score: 2, Insightful

      > Who's going to want to buy it? I mean, it's a list of drug addicts--their CREDIT scores are going to suck!

      It's *Virginia*, for Pete's sake. Since I visited there a year ago, I remember driving through Arlington and Alexandria - two bedroom suburbs of Washington, DC. Obviously politicians would want to keep their problems out of such a database - heck, anyone would. Most probably some politicians, political workers, lobbyists, and such are among those 8 million names. Their credit scores won't suck, and they have more reason to keep their names hidden.

      --
      The living have better things to do than to continue hating the dead.
    4. Re:Non-story? by Nutria · · Score: 2, Insightful

      Not everything is a sign of government incompetence. Sometimes it's just a case of everyone getting off Christmas Day.

      --
      "I don't know, therefore Aliens" Wafflebox1
    5. Re:Non-story? by pixelpusher220 · · Score: 3, Insightful

      imagine a world where your healthcare isn't tied to your job....

      It's called most civilized countries other than the US.

      --
      People in cars cause accidents....accidents in cars cause people :-D
    6. Re:Non-story? by Buelldozer · · Score: 2, Insightful

      Oh boy, this is going to make me unpopular.

      Maybe developing software should require a license, or at least an independent review before it is released.

      Maybe connecting a computer to the internet should require a license, or at least an independent review of the users skill level.

      I promise I'm going to defend those two statements in just a bit.

      Here on /., and other tech oriented websites, I often see Internet access put into the same category as traditional utilities. People want it reliable, ubiqutious, interoperable, and as low cost as possible.

      Like a traditional utility it should be brought to as many people as possible because it can demonstrably increase people's quality of life.

      I also see a lot of people calling for Internet access to be regulated like a utility. As in "just sell the damn pipe and let companies provide service over it". Much like electrical, water, gas, cable, and telephone service.

      Here's the thing, all of those traditional utilities have interoperablity and safety standards. For instance you cannot connect your own natural gas service, electrical service, telephone service, or cable service to your home. Nor can you make your parts and have the relevant agencies use those when your home is connected to those utilities.

      The reason for this is that because it would be dangerous to do so and most people don't have a good idea of what it would take to engineer a solid gas expansion chamber, electric pole insulator, or the myriad of other gear it takes.

      The gear that is used must be designed by a PE (Professional Engineer) and submitted to an independent testing agency, frequently U.L., before it can be sold for those purposed.

      Why all of this designing and testing? Because it's DANGEROUS if you let the common man engineer his own stuff. It could, and would, negatively impact the reliability of the service for all users.

      So here we are. There are increasing numbers of voices asking for Internet access to be considered a traditional utility. Utility services can, and are, damaged, destroyed, and degraded when people who are ignorant or wilfully negligent attach and use unregistered, unlicensed, and untested gear on those utilities.

      Why should Internet access be any different? Why should software company XYZ be given a free pass when their $h1t software is attached to the Internet and allows the comprise of 8 million peoples prescription history?

      I don't like the idea of software developers requiring a license or independent testing of software. I don't like the idea on the hardware side either. It will lead to ridiculous restrictions and increased costs.

      However, if we agree that Internet access is an essential utility then we simply cannot allow every Tom, Dick, and Harry to use whatever crap software they want. We cannot allow these same people to hookup whatever hardware they want. We cannot allow a business to expose its records and data however it wants.

      There is too much at risk and the consequences of poor decisions are too often born by people who cannot control those decisions.

      I am now donning my asbestos suit. I know this idea is unpopular, but hopefully the parallel between the Internet as a utility and a traditional utility is strong enough to make some of you think. Even if you don't agree with me, and many of you won't, you have to agree that we have to do something.

    7. Re:Non-story? by TDO48 · · Score: 2, Insightful

      Following the same line of thought - and a topic that I've been discussing with a few friends and colleagues lately - why is it that the ultimate responsibility, that of creating life... concretely reproducing oneself... is not also regulated. With all the potential for abuse, improper raising, dangers and challenges....

    8. Re:Non-story? by pixelpusher220 · · Score: 3, Insightful

      you do have the one advantage in that you can change jobs without worrying about healthcare issues, this is true.

      But your healthcare *is* tied to your job in the sense that without your job, you wouldn't be able to pay it.

      --
      People in cars cause accidents....accidents in cars cause people :-D
  2. Deleted all the backups??? by Nutria · · Score: 2, Insightful

    Don't these jackasses know what Iron Mountain is, and what tape drives are for???????

    --
    "I don't know, therefore Aliens" Wafflebox1
    1. Re:Deleted all the backups??? by IsThisNickTaken · · Score: 2, Insightful

      Since all the backup data in encrypted, then what's the problem?

  3. Proper backup procedures by Ender_Stonebender · · Score: 3, Insightful

    Hopefully the state of Virginia follows proper backup procedures, and has a copies of the data that are off-site and off-line. It may take a day or so for someone to go fetch the tapes, but the data shouldn't be lost. So the people trying to ransom this data should be screwed.

    --
    Loose things are easy to lose. You're getting your hair cut. They're going there to see their aunt.
    1. Re:Proper backup procedures by jcnnghm · · Score: 5, Insightful

      It's not about being able to recover the data, it's also about everyone's medical records being sold. If medical records can't even be protected at the state level, what makes people believe that national electronic health records will be any safer? Just wait until your laying in the hospital, but you can't be treated because access to your online health records are down.

      I'm increasingly amazed by the willingness of people to bitch and moan about incompetent and inefficient bureaucrats, while at the same time, insisting on turning over more and more important societal functions to these same bureaucrats.

      --
      You don't make the poor richer by making the rich poorer. - Winston Churchill
  4. Was attack over the network or stolen backups? by Anonymous Coward · · Score: 5, Insightful

    10 million records... did he really "download" that over the internet and not get noticed? I guess he did deface their webpage. He's already giving him/herself away. But could it also be that he/she got the backup tapes and stole the data that way? Or did some moron lose their USB key with an export of the data on it? Or, did he/she just deface the web page and spin a story about stealing data?

    1. Re:Was attack over the network or stolen backups? by ledow · · Score: 5, Insightful

      Or none of the above. What about he gained remote access to the backup servers, encrypted their backups with a password of his choosing and deleted their other (presumably, rewritable / otherwise on-line) backups?

      That way, he personally had access to them (without having to download them) and has removed everyone else's access. Even if he has just "lost" the latest backups for them, that's an incredibly serious breach that he could even get that close and relevant to a lot of people. He *could* have downloaded whatever he wanted and could have wreaked enormous havoc by *corrupting* the backups beyond recognition and not even get noticed. How many other large organisations use their host's backup facilities (which are normally run as "on-line" backups with occasional "off-line"/"off-site" backups) instead of their own? I know of several, but they don't host anything anywhere near as critical to this.

      Either way, it's piss-poor server/network management and someone should be fingered for it. I'm guessing it's more likely an "IT Consultant" and/or someone who didn't listen to their systems administrator at the last round of budget estimates than the actual implementors of the system.

  5. Whitehouse take note by 2phar · · Score: 4, Insightful

    A timely illustration of the critical importance of security in electronic medical records.

  6. Stupid criminals by Anonymous Coward · · Score: 1, Insightful

    If it's real it's stupid.

    Can a governmental agency even pay a ransom? Are they allowed? Would they even consider it?

    I would think they would just go to the cops. This makes ransoming the data of a government agency an all risk no reward proposition.

    Maybe you could blackmail the head of IT but you have to keep the threat on the DL and the data going missing is the threat. Also I think 10 mill is out of the question in the later case.

  7. State control by ChrisMaple · · Score: 2, Insightful

    This is what happens when you let the government in to places where it shouldn't be. There shouldn't be a state record of prescriptions, in fact the entire idea of government restricting the sale of certain chemicals to a doctor-monopoly is wrong. You statists are getting what you deserve; unfortunately the rest of us have to pay for it too.

    --
    Contribute to civilization: ari.aynrand.org/donate
  8. An unrelated comment by dachshund · · Score: 5, Insightful

    This is tragic, and please don't view the following unrelated rant as indicating lack of sympathy or some kind of judgement against the public agency that's getting slammed in this case.

    A couple of weeks ago I spent a few days at the RSA security conference, one of the biggest conferences/trade shows in the security industry. Roughly 7 out of 10 of the products being hawked were absolute nonsense: buzzword-compliant BS. "Security risk management" software, hacked-together IDS systems, encryption systems that have pretty Windows GUIs (and probably, lots of pretty Windows code vulnerabilities), AV that's easy to circumvent, etc. They'd do absolutely nothing to protect you in the face of a serious attack. I say this as both a security professional and a business owner, which makes me somewhat well qualified to make that judgement. Often the most obviously ineffective products were the best sellers.

    My point? In terms of commercial spending, "security" has so far been an excuse to spend a bunch of money and check a lot of little boxes. Corporations and organizations aren't really serious about preventing attacks, because for the most part it isn't happening (to most companies). An executive wants to say he "did something", so he buys a bunch of stuff and wastes time configuring it. It probably doesn't protect him against a motivated attacker, and he doesn't have the skills in-house to deal with it (which would be a lot more valuable than the equipment and software he purchased).

    When I see something like this story, well, it's absolutely not gratifying. It's tragic. And of course, the fact that it's hitting a public agency makes it even nastier. But at very least, I hope that things like this do at least scare the crap out of some of the companies buying this nonsense, and convince a few of them to take the problem seriously. Because it is a problem. The reason we have the luxury of pretty trade shows that sell fluffy products is because this very real problem just hasn't manifested itself in an expensive enough way to shock people into taking the problem seriously. I really hope people start taking it seriously before this kind of thing becomes too pernicious.

  9. Ummm... by ledow · · Score: 5, Insightful

    Well... he has an email address that he wants people to talk to him on. The person is asking to be caught already. Even assuming Tor use, etc., that's a definite lead back to him right there. You're talking an open invitation for some agency to coerce Yahoo to plant something on his browser when that login is detected (a cookie would probably do for the simple cases, a Flash/Java/browser exploit or similar in an advert would easily do for the more complex). Hell, I wouldn't be surprised if it wasn't possible to get a Microsoft-signed Java app (and, thus, automatically run without prompting) into the pages that are made for his login with their co-operation and have it reveal the *real* IP address / routing.

    You can *easily* string him along for four or five emails. He would have to be using extremely tight security each and every time in order to communicate safely (and thus I hope he ran / is running a sandboxed system via a good anonymising network for the purpose of creating and checking that mail account each and every time and that he *never* uses that sandbox for anything else).

    And you're talking confidential patient records - this is no hero of the citizenry, it's some pillock with nmap. So I hope he does get caught. Yeah, expose the security holes (though even that is just asking for jailtime) but don't play with people's lives.

    How he expects to receive any money is beyond me... there's no such thing as a "safe" bank account except in the movies. Or is he hoping for a large bag of cash to be thrown from the Golden Gate bridge at 13:37 or similar? I'm guessing that, somewhere, he's made a stupid, elementary and critical mistake which means that he'll be "caught" quite soon (as in, people know who he is and just have to do the paperwork to get him), if he's not already.

    If you want to make a stand, make a stand, target an organisation, pick a purpose, hit the critical points without collateral damage. If you want to dick about and show what a hacker you are, that's when you take whatever you *can* find (e.g. extremely private medical records and personal details of random people) and threaten to spread it unless a ransom is paid. In short,

    Go to Jail. Go directly to Jail. Do not pass Go. Do not collect $10 million.

    1. Re:Ummm... by Mendoksou · · Score: 5, Insightful

      Right, and he intends to get the money somehow... as if it couldn't be tracked. My guess is that this guy is as good as caught, or its a hoax. Either way, expect to see more restrictive internet legislation because of this.

      --
      DISCLAIMER: I am very rarely serious. If the above comment seems asinine makes no sense, it is most likely a bad joke.
  10. Re:Sounds like an inside job. by Culture20 · · Score: 2, Insightful

    Hmm. Here we have a serious security breach but the details are so sketchy we're resorting to ethnic humour and the finer points of grammar to fill in the time. Allow me to offer up my guesses as to what Really Happened(TM): The server was recently migrated to Windows Vista from RedHat, the hackers were Chinese nationals who coordinated their actions using Hotmail accounts, and needed funding for the Virgina health department IT department was cut by Republicans in the stimulus bill. Discuss.

    But Republicans weren't cutting spending recently, only taxes.

  11. Re:Sounds like an inside job. by jotok · · Score: 2, Insightful

    Trivial for FBI to get a warrant for the guy's login details from Yahoo.

    Of course, if he's using TOR, then they're hosed.

  12. Consider the Source by DynaSoar · · Score: 3, Insightful

    "replaced the homepage with a ransom demand."

    What was discovered was vandalism -- an altered web page and deleted data. There's no evidence besides the vandals' word that anything was downloaded. The same source claims the backups were missing, and that they wanted ransom for return of the data. This is Rx tracking data, not financial or personal ID data.

    If it had been personal data, and it'd been downloaded by real ID thieves, they would NOT have notified the world of the event immediately (in fact, while in progress) by defacing the site. They'd have wanted to get away clean and sell off the data if possible before the theft was noticed. And they'd have sold it rather than proving their stupidity by demanding ransom. If they couldn't sell it they'd trash it rather than risk getting caught.

    The site collects data from Rx dispensing sites across the state. All the data exists elsewhere, making the claim of no backups irrelevant. This site simply puts in one place what's spread out and not commonly available, so other dispensing sites can know whether someone's getting too much controlled prescription meds. Everything that was deleted can be re-obtained from the same places it was gotten all along.

    The incident is a HIPAA violation. The FBI investigates those as well as computer security issues, explaining their presence in light of the fact that no real damage was done. If it were an inside job, it wouldn't have been done because nothing of value was to be gained from that particular collection of data, and an insider would know that. From the inside there are far more valuable collections of data that could be had from that system, such as payment records for license fees of registered Virginia health professionals.

    The presence of the FBI and the "neither confirm nor deny" response of Va DHP, and those facts being realted by WP, makes it seem like there's a story here. Not hardly.

    --
    "I may be synthetic, but I'm not stupid." -- Bishop 341-B
  13. Does he pass the Hakcer Intelligence Test? by Tolvor · · Score: 3, Insightful

    Time for the Hacker Intelligence test

    It's easy to break something. It's much harder to completely cover the evidence of who is responsible.

    Question 1 - Why did the hacker target the Virginia Health Department?? That wouldn't be a site that most hackers would even think about much less target for major intrusion. Did the hacker in question cover his tracks as to why he chose this obscure site? Might he have been familiar with it because it tracks potential perscription drug abuse, and he had been flagged for further investigation before? Does he have a history with this company?

    Question 2 - Did he cover his visits? Few people can find a potential site, explore the site for vulnerabilities, get access to the site, explore the internal structure of the site, devise an attack plan, code it, execute it, and get out in just one sitting. It usually requires several sessions, each time gaining more access and having better intelligence. The last visit can be covered up, but did he cover up the logs of the first few times when he didn't have complete control, and his tracks and actions may still be in an access log?

    Question 3 - What methodology did he use to gain access? Having access to the database (and backups) to the degree that an encryption command can be executed would be difficult. It requires the ability to execute several commands remotely on the server. Were these commands given thru web-page vulnerabilities? Did it require log-in credentials, and if so, whose? Did access require special in-house knowledge, and if so, who knew it?

    Question 4 - Where did he do this from, and what is his IP address? Hiding your IP address is next to impossible and there are multiple logs kept of access, including by the ISP. Did he do this from home? (If so, FAIL) Did he do this from a public wireless access point? If so did he cover his tracks there? (It's amazing where they put surveillance cameras nowdays) Anonymizer services will usually hand over the original IP addresss if requested by federal authorities, so that isn't going to work. Did the hacker consider that?

    Question 5 - Where is he checking that yahoo address from? See question 4.

    Question 6 - Is he using a different computer now? If I wanted to be really sneaky I'd ask yahoo to check not only the Yahoo cookie when someone logs into that account, but *also* get the Google one also, and 10 others. Send the cookies to the relavent companies for the data it contains. Is he using a fresh computer to erase tracks left there?

    Question 7 - Did he cover up his phrasing carefully from others he used pubicly? Phases like "Uhoh" "gladly" "not to pony up" "Fucking Bunch of Idiots" "bettin'" "drop me a line" "to have gone missing, too" (weird extra comma here and other places) seem to be rather unique. Some of it can be faked, but the phrasing we use says a lot about us.

    Question 8 - How is he planning on collecting the money? Most people think international banks (Caymen islands is common) is the answer. No. Most countries/locations (ex Caymen islands) have easy business registration/taxation rules, but are poor choices for trying to stash/launder money. It's not easy collecting large amounts of money. Does the hacker have a plan on how to collect that money?

    Question 9 - Is he going to revisit the scene of the crime? Is he checking the internet news sites to find stories about m^Hthis crime? Is he going to give himself away by visiting such a site (like Slashdot) and visiting, leaving his IP address. Who knows, maybe he'll even gladly, comment. ;)

    Comments can be left at hackingforprofit(the at sign)gmailcom. Drop me a line. ;)

  14. Re:Sounds like an inside job. by mewsenews · · Score: 2, Insightful

    Leaking the entire database to identity thieves is part/most/all of the hacker's threat if the ransom is not delivered. If the database is lost and they have to start from scratch -- big deal. If the database is lost AND in the hands of well paying criminals -- uh oh.