NHS Staff Hit by Almost 140,000 Malicious Emails in 2020

NHS Staff Hit by Almost 140,000 Malicious Emails in 2020

Official figures from NHS Digital show that NHS staffers were hit by 137,476 malicious emails last year.

The data, obtained under the Freedom of Information Act by the Parliament Street think tank, revealed that NHS staff reported 27,958 suspected phishing emails targeting the NHSmail email service in 2020. Additionally, health workers reported 109,491 suspected spam emails throughout the year.

The highest month for reported attacks was January (29,355) followed by March (28,855), the latter being when the strictest COVID-19 lockdown restrictions were introduced in the UK last year.

Interestingly, the figures highlighted a steady decline in the number of suspicious emails reported to NHS Digital from April to December, decreasing from 11,068 in April down to 4382 in December.

Chris Ross, SVP, international, Barracuda Networks, commented: “These figures are a reminder that when it comes to stealing confidential data and wreaking havoc, cyber-criminals still consider our health service to be fair game. Unfortunately, these scam emails are often incredibly realistic, lulling the victim into a false sense of security to hand over passwords, patient records and sensitive information by impersonating legitimate brands and even fellow employees.”

With the global pandemic putting a huge strain on hardworking doctors, nurses and clinical staff, it’s absolutely vital that email systems are properly protected from outsider threats, to block malicious emails before they reach the inbox, he added.

“It is equally important for Trusts to issue the necessary guidance about the risks associated with phishing attacks, so that staff are aware of the techniques used and can think twice before handing over important information to suspicious third parties.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Europol Breaks $14m Card Fraud Ring

Europol Breaks $14m Card Fraud Ring

Europol is claiming to have helped dismantle an organized crime group that defrauded US banks out of an estimated €12m ($14.4m)

One a single day in October last year, an international police team led by the Spanish National Police (Policía Nacional) and the US Secret Service carried out 40 house searches, arrested 37 suspects and seized 13 luxury cars. As a result of Operation Secreto, they also froze 87 bank accounts holding a total of €1.3m (£1.6m). 

The scheme, masterminded mainly by Greek nationals, involved the setting up of shell companies in the US with associated bank accounts and cards. Spanish retailers in on the scheme would then max out credit lines on issued cards before laundering the funds via other accounts in various European countries.

Over 50 US banks were defrauded in this way, according to Europol, which coordinated the operation with additional help from police in Austria, Denmark and Greece, as well as the US Department of Justice and the US Financial Crimes Enforcement Network (FinCEN).

“Europol facilitated the information exchange, the operational coordination and provided analytical support for this eight-months long investigation,” it explained.

“During the operation, Europol set up a coordination center at its headquarters with the use of a virtual command post to enable liaison officers from the involved countries, Europol experts and a representative from Eurojust to coordinate the operational activities. Europol also deployed an analyst to Greece to provide real-time analytical support to investigators on the ground.”

In total, the operation led to 88 house searches, 105 arrests, the seizure of 14 luxury cars and €406,000 in cash, as well as the aforementioned frozen bank accounts.

A well-publicized leak of FinCEN data last year revealed around $2tn in global money laundering activity, although even this is thought to be just the tip of the iceberg.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Tens of Thousands of Patient Files Leaked in US Hospital Attacks

Tens of Thousands of Patient Files Leaked in US Hospital Attacks

Patients and employees from 11 hospitals in the US have had their personal information exposed after hackers reportedly published tens of thousands of records online.

The files come from Leon Medical Centers, which runs eight facilities in Florida, and Nocona General Hospital, which has three in Texas.

The compromised information includes patients’ names, addresses and birthdays, medical diagnoses and letters to insurers. Also exposed was a folder containing background checks on hospital staff, according to NBC.

The unnamed attack group is apparently well known to researchers and is usually in the business of double extortion ransomware, whereby data is stolen and posted to a dark web blog in a bid to force payment.

However, it’s unclear why so many records were published in the first instance. Usually such groups post a small slice of what they have to prove they mean business, and only expose large volumes of data in retribution if the victim organization refuses to comply.

Adding further mystery to the case, an attorney for Nocona General Hospital told the US news network that the organization does not appear to have suffered any ransomware infection or received a ransom demand.

In the case of the other victim, Leon Medical Centers announced last month that it had been breached in November 2020, in a raid that compromised: patients’ names, contact info, Social Security numbers, financial information, dates of birth, family information, medical records, prescription information, diagnosis and treatment history, and health insurance information.

However, in a filing with the US Department of Health and Human Services, only 500 individuals were thought to have been exposed.

Cyber-attacks on global healthcare organizations (HCOs) surged by 45% in the final two months of 2020 versus the previous two months, more than double the rate of those targeting other sectors, according to Check Point.

Ransomware recorded the largest increase overall and poses the biggest threat to HCOs, the vendor claimed.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Crypto Fund Founder Pleads Guilty to $100m Fraud Scheme

Crypto Fund Founder Pleads Guilty to $100m Fraud Scheme

The founder of two cryptocurrency hedge funds has pleaded guilty to securities fraud after apparently defrauding investors out of almost $100m.

Australian national Stefan He Qin, 24, launched Virgil Sigma and VQR in New York in 2017 and February 2020 respectively. The former purported to earn money from an algorithm which took advantage of market price differences between digital currencies, while the latter employed a number of trading strategies.

Together, the funds are said to have accrued over $114m under management from dozens of investors.

However, Qin had been stealing from Virgil Sigma since 2017, using it as a personal “slush fund” for investments in other cryptocurrency assets and property, including rental of a New York penthouse apartment, according to the Department of Justice (DoJ).

He’s said to have repeatedly lied to investors about their capital, including sending them false account statements, “tear sheets,” and K-1 tax forms.

Virgil Sigma continued to grow thanks to his misrepresentations and was even profiled in the Wall Street Journal in 2018, drawing a new influx of investors to the scheme.

However, by summer 2020 things were unravelling, with Qin forced to raid money invested in VQR to pay investors in Virgil Sigma who wanted to cash out. He also persuaded some of the latter to reinvest their ‘funds’ into VQR even though there was no money left to transfer.

In total, investors were apparently defrauded out of nearly $100m by Qin.

Sentencing is set for May 20 2021. One count of securities fraud carries a maximum term of 20 years behind bars.

Cryptocurrency fraud schemes like this are an increasingly popular way for fraudsters to get their hands on a lot of cash.

Just last week a man was charged with securities fraud after allegedly tricking investors out of $11m in an elaborate scheme which used actor Steven Seagal to promote a fake company.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk