just_david Posted May 12, 2017 Posted May 12, 2017 (edited) Have a friend working in NHS IT, apparently this is europe wide not just nhs. Santandare an O2 also effected And has something to do with a vulnerability in google chrome (unconfirmed), it didn't come in via an email. https://www.theguardian.com/society/2017/may/12/hospitals-across-england-hit-by-large-scale-cyber-attack Edited May 12, 2017 by just_david 2
Garacesh Posted May 12, 2017 Posted May 12, 2017 The second tweet there sums up my reaction. +1 I mean it takes some special kind of [rudies] to write ransomware anyway, but to attack hospitals is just.. sociopathic. Have a vaguely-friend-acquaintance who's an IT tech in the NHS. I'll have to check in, see if her hospital's been hit.. Not that I could do anything anyway. 1
mikkydoos Posted May 12, 2017 Posted May 12, 2017 Primary school near me had their MIS server ransomwared a couple of years ago. Lost everything.
Garacesh Posted May 12, 2017 Posted May 12, 2017 I'm at work right now and it is complete mayhem! Ah yeah, you've moved to the NHS recently haven't you.. Blimey. Baptism by fire, 'eh?! Best of luck!
ICTDirect_Dave Posted May 12, 2017 Posted May 12, 2017 Goodness! What utter B**t***s! Thoughts with you lot who have to fix this!
gh5000 Posted May 12, 2017 Posted May 12, 2017 Time to start taking bets: which political party will be the first to politicise... That's got to have been going undetected for a while to spread throughout the whole NHS. Or are some Trusts down to protect themselves from other Trusts I wonder 2
RLR Posted May 12, 2017 Posted May 12, 2017 Time to start taking bets: which political party will be the first to politicise... That's got to have been going undetected for a while to spread throughout the whole NHS. Or are some Trusts down to protect themselves from other Trusts I wonder Doesn't look to be just the NHS: https://www.bleepingcomputer.com/news/security/telefonica-tells-employees-to-shut-down-computers-amid-massive-ransomware-outbreak/
googlemad Posted May 12, 2017 Posted May 12, 2017 We've had a rumor it is something to do with RDP Our local systems don't seem to have been hit thus far, we're killing off most links to other community sites though (all 140+ of them!) 1
RLR Posted May 12, 2017 Posted May 12, 2017 We've had a rumor it is something to do with RDP Our local systems don't seem to have been hit thus far, we're killing off most links to other community sites though (all 140+ of them!) This is on the Sysadmin subreddit: "Saw a tweet saying they are moving through the N3 backbone. Using the MS17-10 SMBv1 exploithttps://technet.microsoft.com/en-us/library/security/ms17-010.aspx" Not sure if it's true. 1
Garacesh Posted May 12, 2017 Posted May 12, 2017 (edited) Ransomware apparently identifies itself as 'Wana Decrypt0r 2.0' https://twitter.com/MattBobRoss/status/863041065556856832/photo/1 Rumour from people watching the blockchain is that it looks like ransoms are being paid. Edit: NHS have released an official statement. As at 15.30, 16 NHS organisations had reported that they were affected by this issue. Edited May 12, 2017 by Garacesh
victory2015 Posted May 12, 2017 Posted May 12, 2017 i have taken precautions and made our backup shares read only!
googlemad Posted May 12, 2017 Posted May 12, 2017 If you want a laugh the BBC have a 'live report' on the news site, with lots of doctors writing in to moan they can't access their email or whatever... I'm just waiting for one to write in pondering when the systems will be back online 1
Asgard Posted May 12, 2017 Posted May 12, 2017 This has just been posted on the JISC Uk Security Mailing List I'm sure that by now most of you are aware of the issues affecting several NHS trusts. The malware in question appears to be a new variant of wcry. Early indications are showing that this is exploiting MS17-010 which is a vulnerability in Microsoft Server Message Block 1.0 SMBv1. Further information on this particular issue is available here https://technet.microsoft.com/en-us/library/security/ms17-010.aspx Recommended best practice is not to expose your infrastructure to these services, if you are concerned that you are vulnerable to this then disabling SMBv1 is recommended. https://blogs.technet.microsoft.com/filecab/2016/09/16/stop-using-smb1/ There is a thread covering the issue on the CISP website.
victory2015 Posted May 12, 2017 Posted May 12, 2017 the criminal thing is a lot these nhs trusts still using windows xp!! 1
gh5000 Posted May 12, 2017 Posted May 12, 2017 And NHS staff starting their PC up to show journalists and take pictures for Twitter. You're helping spread the virus! You know what a virus is don't you doctor 1
mikeprice Posted May 12, 2017 Posted May 12, 2017 My Oh works for the NHS - not in IT#They have been getting messages for some time reminding them not to open dodgy emails - they have been also getting phone calls 'from IT' trying to get access to their PC via Teamviewer and such like she hasn't seen/heard any herself but there have been many waarnings which implies that a lot of people have had such calls and reported them seems like someone has been after at least part of the NHS for a while
googlemad Posted May 12, 2017 Posted May 12, 2017 In our Trust we have about 100 XP PCs left, then 2/3 Server 2003, about 15 Server 2008 then the rest Server 2008 R2 / 2012 / 2016 although by the sounds of things this attack could affect any of those operating systems we took down most of the pre 2008 R2 stuff initially. The problem will have been some idiot opening a dodgy email with an 'invoice' or similar and boom infection starts spreading, we can put notice after notice on the intranet, the staff bulletins etc but most users won't pay a blind bit of attention! Doesn't help when the emails have become so clever they can now appear to originate from a genuine user with a genuine NHS address. To be honest I left the scene quite early as there wasn't much I could do, in education you could probably just knock off the entire server room for a bit but it is a bit more tricky in healthcare sadly. I know we knocked the VEEAM box off to help prevent the chance of the backups becoming infected. No doubt there is going to be a good few weeks of aftershock...
MatthewL Posted May 12, 2017 Posted May 12, 2017 Got it in one there googlemad, I spent 8 years in the NHS and I've seen it all. Further up the topic there was mention of the N3 backbone, the ACL's on this network are quite strict which would prevent spread, it just happens to be a coincidence this. Also the network isn't as open as you think!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now