AIIMS Ransomware Attack: Experts Say Key Data Of Patient At Risk Of Leak, Sale On Dark Web

AIIMS Ransomware Attack: Experts Say Key Data Of Patients At Risk Of Leak, Sale On Dark Web

The experts said the exploited databases contain Personally Identifiable Information (PII) of patients and healthcare workers, as well as administrative information such as blood donor records, ambulance records, vaccination records, caregiver records, login credentials.

Updated: November 26, 2022 7:18 PM IST

By India.com News Desk | Edited by Manmath Nayak

AIIMS-Delhi Server Down: Hospital Issues Fresh SOPs. Read Here
In the meantime, the AIIMS officials said that all affected online patient services are now being run on manual mode.

AIIMS Ransomware Attack Latest Update: As the All India Institute of Medical Sciences (AIIMS) in New Delhi is still struggling to get its servers up and running after a massive ransomware attack earlier this week, cyber-security researchers on Saturday said the most reported attacks in the healthcare industry, which rose during the pandemic, involve the leak or sale of databases on the Dark Web.

They also added that the exploited databases contain Personally Identifiable Information (PII) of patients and healthcare workers, as well as administrative information such as blood donor records, ambulance records, vaccination records, caregiver records, login credentials, etc.

“Government agencies involved in the healthcare industry should abide by HIPAA’s (Health Insurance Portability and Accountability Act) compliance requirements, create awareness among users regarding cyber-attacks, online scams, and phishing campaigns, set up policies for secure passwords and enable multi-factor authentication (MFA),” a spokesperson of AI-driven cyber-security firm CloudSEK told IANS.

The cyber attack on AIIMS shut down its main and backup servers.

Earlier this week, the attackers hacked the e-hospital service which manages the patient data system, affecting the outpatient department (OPD) and sample collection services. Those behind the cyber attack have warned AIIMS to “prepare for a negotiation”. Delhi Police are investigating the cyber attack.

In the meantime, the AIIMS officials said that all affected online patient services are now being run on manual mode.

According to CloudSEK, a massive spike in cyberattacks on healthcare organisations has been witnessed during the pandemic.

“Our research shows that in the first four months of 2022, the number of cyberattacks on the industry rose by 95.34 per cent compared to the same period in 2021. The Indian healthcare sector was the second most targeted when it comes to cyberattacks worldwide,” the company spokesperson said.

Protecting patients’ medical and financial information has emerged as a new challenge for healthcare organisations.

According to Indusface, an application security SaaS company, there were more than 1 million cyber attacks of various types across Indusface’s global healthcare clientele.

Of these, 278,000 attacks were reported in India, highlighting the vulnerabilities of the Indian healthcare sector.

CloudSEK research revealed recently that immediate challenges to the healthcare sector include phishing and BEC (business email compromise), ransomware attacks, DDoS (Distributed Denial of Service) attacks, insider threats, critical infrastructure and ‘Medjacking’, etc.

In August this year, the UK’s National Health Service (NHS) was hit by a ransomware attack via a third-party vendor.

(With inputs from IANS)

Also Read:

For breaking news and live news updates, like us on Facebook or follow us on Twitter and Instagram. Read more on Latest India News on India.com.

By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts Cookies Policy.