Cyber Turmoil in the Healthcare Sector: Boston Scientific
Over the weekend, two prominent healthcare companies, Boston Scientific and McKesson, revealed further details regarding separate cyber incidents. Boston Scientific, whose information technology systems were compromised by unidentified assailants last week, reported that the attack is still in progress. Pacemakers and cardiac devices implanted after the breach on August 25 are unable to perform remote monitoring or data transfer as designed. Quite the mess, huh?
Pacemaker Interruptions
The medical technology company mentioned, “New remote monitoring communicators are not able to be activated. Device data will NOT be sent to remote patient management systems until such time as the communicator can be activated.” This issue applies to all new cardiac rhythm management implants excluding insertable cardiac monitors (ICM). Isn’t tech fantastic when it’s supposed to simplify life, right?
ICM Conundrum
As a result of the cyber incident, “new ICMs cannot connect to the patient remote monitoring smartphone,” the update explained. Events logged by the ICM will not be transmitted until the ICM connects with the patient mobile app. Patients can still share episodes in person via the Clinic Assistant app by tapping the “interrogate” button. Might need Inspector Gadget for this one!
Restoration Dilemma
Boston Scientific is currently focused on restoring system access. The digital breach has impacted production, distribution, and ordering processes. “We are diligently striving towards partial restoration,” the company reported. CrowdStrike has been enlisted for assistance, and no cloud-based systems were involved. No unauthorized IT activity has been observed since August 25. No specific timeline yet, but fingers crossed!
ShinyHunters Attack: McKesson’s Incident
Meanwhile, McKesson acknowledged a security breach after ShinyHunters boasted about infiltrating the company’s Snowflake and Salesforce environments, gaining access to patient data. “Unauthorized entry into specific third-party applications and data exfiltration was linked to a portion of customers,” stated Francisco Fraga, McKesson’s technology chief. Quite the digital debacle, this one!
Patient Data Theft
ShinyHunters alleged they have accessed over 284 million patient records, demanding a payment of $55.2 million from McKesson. But take this with caution. As the saying goes, treat numbers with skepticism unless you can verify the source. The purportedly stolen data comprises sensitive patient information including full names, addresses, Social Security numbers, and details about cancer.
Voice Phishing Triumph
The unscrupulous group gained access to McKesson’s Snowflake and Salesforce systems by using voice phishing tactics on “multiple employees.” This marks their latest attack, having targeted other healthcare providers recently. Those unfortunate individuals might have believed it was a legitimate call. It’s akin to trusting your dog with your meal—risky move!
Conclusion: When Tech Mishaps Make the News
These cyber escapades serve as a reminder that technology can be a double-edged sword. Whether it’s Boston Scientific’s struggle with pacemakers or McKesson’s troubles regarding patient data, technology is serving up more drama than an overly cooked Sunday roast by your grandmother. Stay secure, and keep a watchful eye on those devices!
For the latest updates, visit GadgetLad.