HHS Issues New Guidance On SamSam Ransomware

Stu Sjouwerman | Apr 11, 2018

fbi-and-microsoft-warn-of-samas-ransomware-501914-3HHS' Healthcare Cybersecurity and Communications Integration Center released a report March 30 on SamSam, an ongoing ransomware campaign that has targeted the healthcare and government sectors since 2016.

There have already been at least eight SamSam attacks on healthcare and government organizations since the beginning of 2018, including attacks on two Indiana-based hospitals and EHR provider Allscripts, which faces a class-action lawsuit as a result of the attack, according to the report obtained by the American Hospital Association.

"The attackers have remained focused on [government and healthcare] ... likely because those systems and networks are critical and any downtime cannot and will not be tolerated, which increases the chance that the victims' will pay the ransom," the report reads.

The report outlines mitigation, contingency and business continuity strategies for healthcare organizations to reduce a ransomware attack's impact. One of the HCCIC's core recommendations is to avoid paying a ransom.

Here are four key factors an organization should consider prior to paying a ransom.

1. Paying a ransom does not guarantee an organization will regain access to their data

2. Some victims who paid the ransomware demand were later targeted again by cyberattackers

3. After paying an initial ransom, some victims were asked to pay an additional amount to receive the promised decryption key

4. Paying the requested ransom could inadvertently encourage cyberattackers to continue to engage in this type of criminal business model

To access HCCIC's report, click here.

https://www.aha.org/system/files/2018-04/corrected-HCCIC-2018-002W-SamSam-Ransomware-Campaign.pdf

Topics: Ransomware

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.