EHR Vendor Faces Legal Action Over Data Breach

EHR Vendor Faces Legal Action Over Data Breach

A Tennessee-based healthcare technology services company is facing legal action over a cyber-attack that occurred in August 2021.

The class action lawsuit was filed against QRS Healthcare Solutions (QRS, Inc), an electric health record (EHR) vendor and provider of integrated practice management and clinical services, including electronic patient portals.

On August 26 2021, QRS discovered that a cyber-attacker had accessed a QRS dedicated patient portal server on which certain sensitive information was stored.

According to a data security notice published by QRS on its website, the cyber-attack “involved the personal information, including the health information, of some of its clients’ patients.”

The impacted server was taken offline when the attack was discovered, and QRS hired a digital forensics security firm to analyze the incident. 

Investigators determined that an unknown attacker had accessed the server from August 23 2021 to August 26 2021, and may have acquired files containing the protected health information (PHI) of almost 320,000 patients.

“The information may have included, depending on the individual, their name, address, date of birth, Social Security number, patient identification number, portal username and/or medical treatment or diagnosis information,” reads QRS’s notice.

In October, on behalf of its clients, QRS began sending written notifications to individuals whose personal information was accessed in the incident. The healthcare technology services company also offered complimentary identity theft protection services to individuals whose Social Security numbers may have been compromised.

Following the data breach, Kentucky resident Matthew Tincher has filed a class action complaint in the US District Court for the Eastern District of Tennessee against QRS. Tincher, who lives in Frankfurt, alleges that QRS failed to take reasonable action to secure, monitor and maintain the personally identifiable information (PII) and PHI stored on its patient portal.

The suit alleges that the data was stored by QRS in an unencrypted form. It also criticizes QRS for waiting two months before sending out data breach notifications to impacted individuals. 

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Nova Scotia Seeks to Improve Cyber-Bullying Law

Nova Scotia Seeks to Improve Cyber-Bullying Law

The government of Canadian province Nova Scotia is seeking public feedback on improving anti-cyber-bullying legislation enacted in July 2018.

Nova Scotia was the first Canadian province to enact a detailed law addressing cyber-bullying and the unauthorized sharing of sexually explicit imagery.

The law, known as the Intimate Images and Cyber-protection Act, was created to discourage individuals from bullying others via the internet, over email or through text messages. It further sought to dissuade people from sharing intimate images of individuals without their consent.

Under the Cyber-protection Act, cyber-bullying victims and their families are permitted to participate in dispute resolution programs and can get protection orders issued against alleged offenders to cease their cyber-bullying activities. The law also allows victims and their families to request the deletion of online content, to prohibit further contact, and to seek compensation for their virtual harassment. 

The Cyber-protection Act also established the CyberScan Unit that helps cyber-harassment victims navigate the justice system and comprehend their options. Since its launch four years ago, the CyberScan unit has helped victims in 660 cases.

Built into the law is a mandate for Canada’s justice minister to review its implementation and submit a report on their findings to the Nova Scotia House of Assembly within four years.

“We want to help keep people safe online, so it is important that we review the legislation to ensure that it remains effective,” said justice minister and attorney general Brad Johns.

He added: “The feedback we receive will be valuable in helping us see where we can improve the legislation.”

The consultation phase for the review of the Intimate Images and Cyber-protection Act began on January 6. It was kicked off with the creation of an online survey designed to capture public sentiment surrounding the law. 

This survey is open to Nova Scotians aged 16 or older. Submissions for the survey must be completed by January 28.

In concert with the survey will be a series of virtual focus group sessions run with various stakeholders, including victims and their families, provincial victim-services staff, judges, police, lawyers, scholars and advocates.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Accellion Reaches $8.1m Data Breach Settlement

Accellion Reaches $8.1m Data Breach Settlement

Californian technology company Accellion Inc has reached an $8.1m settlement to resolve a legal claim relating to a data breach in December 2020.

The class action lawsuit was filed on behalf of victims whose personal information was exposed during a cyber-attack on Accellion’s file transfer appliance (FTA).

Accellion had been using the FTA for more than 20 years to securely share files deemed too sensitive or large to be sent over email. Before the cyber-attack occurred, Accellion actively phased out the FTA and encouraged its clients to use a newly developed file transfer solution named Kiteworks. 

Four months before the legacy file transfer solution was due to be retired on April 30 2021, it was attacked by two advanced persistent threat (APT) groups linked to FIN11 and the CLOP ransomware gang.

By exploiting unpatched vulnerabilities in the FTA, the attackers were able to gain access to the files of Accellion’s clients from which they exfiltrated a sizable amount of data.

Sensitive data potentially compromised and stolen in the incident included names, contact information, dates of birth, Social Security numbers, driver’s license numbers and healthcare data.

Many Accellion clients were impacted by the breach, including Shell, The University of California, Stanford University School of Medicine, Bombardier, University of Miami Health, Trillium, Community Health Plan and Kroger.

Accellion identified a zero-day vulnerability in the product in mid-December 2020 and released a patch to address the flaw. By February 2021, four additional vulnerabilities associated with the platform were disclosed and issued CVEs.

The class action lawsuit accused Accellion of failing to implement and maintain appropriate data security practices to protect its clients’ sensitive data and failing to detect vulnerabilities in the security of its FTA. Plaintiffs also alleged that Accellion failed to disclose the inadequacy of its security practices.

According to documents filed in Californian federal court, Accellion accepts no liability for the breach and has denied all of the allegations. The tech company has proposed a settlement that includes $8.1m to cover the claims, notices and administration costs of Accellion FTA users.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Former Inspector General Pleads Guilty to Software Theft

Former Inspector General Pleads Guilty to Software Theft

A former acting inspector general for the US Department of Homeland Security (DHS) has pleaded guilty to charges related to his theft of federal government software and databases.

Charles Edwards, 61, of Sandy Spring, Maryland, worked for the DHS Office of Inspector General (DHS-OIG) from 2008-2013, and before that at the US Postal Service Office of Inspector General (USPS-OIG).

At both organizations, he’s said to have had access to case management software and other systems that contain employees’ highly sensitive personal details.

After leaving the government and setting up his own Maryland-based business, Delta Business Solutions, Edwards apparently stole some of this software and databases containing employee personal information in a bid to develop his own version to sell back to the government.

Edwards pleaded guilty in the US District Court for the District of Columbia to conspiracy to commit theft of government property and theft of government property.

One of his assistants at the DHS, Murali Venkata, 56, of Aldie, Virginia, has pleaded not guilty to charges related to the conspiracy, and his case remains pending.

It’s alleged that Venkata and others helped Edwards in this scheme by reconfiguring his laptop so it could upload the stolen software and databases, providing troubleshooting support and helping him build a test server at his home with the stolen software and data.

Edwards was also said to have retained a team of software developers in India to work on the project.

 In 2014, a bipartisan investigation found that Edwards had “jeopardized the independence of the Office of Inspector General and that he abused agency resources.”

He’s said to have rewritten and delayed critical audits at the request of DHS officials and maintained inappropriate personal relationships with staff.

OIGs are supposed to be independent auditing, inspection and investigative bodies linked to major federal government agencies

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Two Years for Romance Fraudster Who Targeted 670 Women

Two Years for Romance Fraudster Who Targeted 670 Women

A romance scammer who targeted hundreds of women and persuaded some to give him thousands of pounds has been jailed for over two years.

Osagie Aigbonohan, 41, from Lagos, Nigeria, operated under the moniker “Tony Eden” from his flat in Abbey Wood, London.

He’s said to have targeted nearly 700 women, including one who was terminally ill and whom he continued to pursue even after she passed away.

Police who searched his property also found footwear he’d purchased linked to one of his victims.

Another was tricked into paying Aigbonohan £9500 in nine separate transfers after he sold her a line that he had been impoverished by paying for the funerals of several people who’d died in a machinery accident.

The money went into various accounts held under fake identities before being funneled back to Aigbonohan’s own account. At least eight other women are thought to have given him money, totaling an estimated £20,000.

He was sentenced to 28 months at Southwark Crown Court on Friday after pleading guilty to fraud and money laundering charges.

Police arrested Aigbonohan back in July 2021 and found he was living with a false driving license, having overstayed his visa in the UK for two years.

“Romance fraud is a particularly callous offense, involving exploitation of an individual’s emotional needs and caring qualities, to extract money from them. People should be particularly vigilant over the coming month as we head towards Valentine’s Day and more people seek a partner,” warned James Lewis of the Crown Prosecution Service (CPS).

“Aigbonohan demonstrated a cynical disregard for his victims, grooming them with romantic promises before dishonestly persuading them to provide him with financial assistance.”

Action Fraud claimed last week that romance fraudsters conned their victims out of £92m between November 2020 and October 2021. Police warned that the period between Christmas Day and Valentine’s Day is the most dangerous for lonely hearts as scammers are out in force scouring the internet for victims

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Microsoft Warns of Destructive Malware Campaign Targeting Ukraine

Microsoft Warns of Destructive Malware Campaign Targeting Ukraine

Microsoft has detected a major malware wiper campaign targeting government, IT and non-profit organizations across Ukraine.

Dubbed “WhisperGate,” the attacks were first spotted on January 13, at around the same time that over a dozen government websites were forced offline in what was described as a “massive” cyber-attack.

Although Microsoft said it had not noticed any links between the destructive malware campaign, tracked as DEV-0586, and previous known activity groups, it comes at a time of heightened tensions with Russia, which is once again threatening Ukraine with invasion.

The malware, “which is designed to look like ransomware but lacking a ransom recovery mechanism,” has been found on “dozens” of systems, although it may have spread far wider, Microsoft warned.

“The two-stage malware overwrites the Master Boot Record (MBR) on victim systems with a ransom note (Stage 1). The MBR is the part of a hard drive that tells the computer how to load its operating system. The ransom note contains a Bitcoin wallet and Tox ID (a unique account identifier used in the Tox encrypted messaging protocol) that have not been previously observed by the Microsoft Threat Intelligence Center (MSTIC),” the blog post noted.

“The malware executes when the associated device is powered down. Overwriting the MBR is atypical for cybercriminal ransomware. In reality, the ransomware note is a ruse, and that the malware destructs MBR and the contents of the files it targets.”

The second stage malware is hosted on a Discord channel and designed to locate specific file extensions, overwrite the contents, and rename the file with a random four-byte extension.

Microsoft urged affected organizations to search for the relevant IoCs, investigate any anomalous authentication activity and enable multi-factor authentication (MFA) and controlled folder access (CFA) in Microsoft Defender to prevent MBR modification.

Senior manager for tactical defense at F-Secure, Calvin Gan, argued that WhisperGate has echoes of the infamous NotPetya campaign tied to the Russian state.

“With the usage of wiper malware, it is clear that the attackers are not after financial gain but are more motivated to cripple the target operations. Overwriting the MBR would render the machine unbootable, thus making recovery impossible, especially when the malware also overwrites file contents before overwriting the MBR,” he said.

“While the attacker’s true intention of deploying wiper ransomware coupled with file corrupter is not known at the moment, having it targeting government agencies and associated establishments is a sign that they want operations in these organizations ceased immediately. Perhaps the Bitcoin wallet address and communication channel in the ransom note of WhisperGate is a smokescreen to divert the attention of the attacker’s true intention of the attack while making it harder to track them.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

An Examination of the Bug Bounty Marketplace

Here’s a fascinating report: “Bounty Everything: Hackers and the Making of the Global Bug Marketplace.” From a summary:

…researchers Ryan Ellis and Yuan Stevens provide a window into the working lives of hackers who participate in “bug bounty” programs­ — programs that hire hackers to discover and report bugs or other vulnerabilities in their systems. This report illuminates the risks and insecurities for hackers as gig workers, and how bounty programs rely on vulnerable workers to fix their vulnerable systems.

Ellis and Stevens’s research offers a historical overview of bounty programs and an analysis of contemporary bug bounty platforms — ­the new intermediaries that now structure the vast majority of bounty work. The report draws directly from interviews with hackers, who recount that bounty programs seem willing to integrate a diverse workforce in their practices, but only on terms that deny them the job security and access enjoyed by core security workforces. These inequities go far beyond the difference experienced by temporary and permanent employees at companies such as Google and Apple, contend the authors. The global bug bounty workforce is doing piecework — they are paid for each bug, and the conditions under which a bug is paid vary greatly from one company to the next.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Russia Stops REvil

Russia Stops REvil

Russia says it has ended the criminal activities of the REvil ransomware gang and placed its members under arrest. 

In an action coordinated by the Federal Security Service of the Russian Federation (FSB) in cooperation with the Investigation Department of the Ministry of Internal Affairs of Russia in the cities of Moscow, St. Petersburg, and Lipetsk, searches were executed at residential addresses associated with 14 gang members.

During the operation, Russian authorities seized computer equipment, money and vehicles purchased with the proceeds of crime. 

statement issued today by the Federal Security Service of the Russian Federation (FSB) stated that “funds were seized at 25 addresses at the places of residence of 14 members of the organized criminal community: over 426 million rubles, including in cryptocurrency, 600 thousand US dollars, 500 thousand euros, as well as computer equipment, crypto wallets used to commit crimes, 20 premium cars purchased with money obtained from crime.”

The FSB said members of the ransomware gang had been detained and charged with the illegal circulation of means of payment.

“As a result of the joint actions of the FSB and the Ministry of Internal Affairs of Russia, the organized criminal community ceased to exist, the information infrastructure used for criminal purposes was neutralized,” reads the statement.

Russia said this blow against REvil was dealt in answer to an appeal by the United States and that US authorities had been “informed about the results of the operation.”

The arrests came after unknown hackers targeted Ukrainian government websites early Friday, blocking access and warning internet users to “expect the worst.”

Former US marine and threat intel specialist at Cyware Neal Dennis commented: “When a group gets as large and prolific as this on the global stage, Russia eventually steps in.

“I don’t think this comes exclusively because the US asked Russia to carry out the operation.”

Chris Morgan, senior cyber-threat intelligence analyst at Digital Shadows, said Russia’s actions could be an attempt to diffuse territorial tensions between Russia and the West.  

“It’s likely that the arrests against REvil members were politically motivated, with Russia looking to use the event as leverage,” said Morgan. 

“It could be debated that this may relate to sanctions against Russia recently proposed in the US, or the developing situation on Ukraine’s border.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains