• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Major Incident declared as NHS computer systems infected by ransomware

Status
Not open for further replies.

northwichcat

Veteran Member
Joined
23 Jan 2009
Messages
32,692
Location
Northwich
I'm surprised there isn't already a thread on this.

BBC News said:
Summary

  • NHS declare major incident after cyber attack on a number of hospital and GP surgeries across England
  • Ransomware software that locks computers, demanding payment, is being seen on screens
  • Similar infections are reported by Spanish utility firms, and in the US, China, Russia, Italy, Vietnam and Taiwan
  • Up to 25 NHS organisations In England are said to have been affected, as well as four GP surgeries in Scotland
  • GPs reported to be using pen and paper in some areas
  • Some hospitals are diverting patients
  • Health Secretary Jeremy Hunt is being briefed by the National Cyber Security Centre
  • Downing Street spokesman says the PM is being kept informed of the situation

http://www.bbc.co.uk/news/live/39901370

I wonder if underinvestment in IT systems is partly responsible. The NHS uses cheap and out-of-date options which aren't really suitable for a large organisation holding large volumes of sensitive information.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

gg1

Established Member
Joined
2 Jun 2011
Messages
2,490
Location
Birmingham
I wonder if underinvestment in IT systems is partly responsible. The NHS uses cheap and out-of-date options which aren't really suitable for a large organisation holding large volumes of sensitive information.

Almost certainly, specifically the fact that a number of NHS trust still use Windows XP, I know for certain that at least one of the affected trusts definitely does.
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,682
Location
Scotland
The NHS uses cheap and out-of-date options which aren't really suitable for a large organisation holding large volumes of sensitive information.
You can levy many charges against the NHS IT system, but being cheap is most definitely not one of them.

https://www.theguardian.com/society/2013/sep/18/nhs-records-system-10bn

An abandoned NHS patient record system has so far cost the taxpayer nearly £10bn, with the final bill for what would have been the world's largest civilian computer system likely to be several hundreds of millions of pounds higher, according a highly critical report from parliament's public spending watchdog.

MPs on the public accounts committee said final costs are expected to increase beyond the existing £9.8bn because new regional IT systems for the NHS, introduced to replace the National Programme for IT, are also being poorly managed and are riven with their own contractual wrangles.
 

DynamicSpirit

Established Member
Joined
12 Apr 2012
Messages
9,213
Location
SE London
I'm surprised there isn't already a thread on this.



http://www.bbc.co.uk/news/live/39901370

I wonder if underinvestment in IT systems is partly responsible. The NHS uses cheap and out-of-date options which aren't really suitable for a large organisation holding large volumes of sensitive information.

Great sympathies for all the people affected by this. It sounds absolutely shocking - already reports of operations being cancelled because of it. Sadly, I guess cyber-crime is so inevitable that it was always going to be only a matter of time before an essential organisation such as the NHS was hit :(

I wouldn't be surprised if you are correct that systems involved are old (bear in mind though that for large organisations it's very much harder to upgrade systems than it is for individuals and small businesses - so running older systems doesn't necessarily imply underinvestment - upgrades often involve testing or even rewriting custom apps to make sure they are guaranteed to work with new operating systems, which can be very expensive to do, and sometimes for very minimal benefit).

However, before we start blaming the NHS, let's be clear that responsibility for this attack almost certainly lies with one group of people, and one group of people only: The criminals who write malware and use it to extort money without any thought for the effect their actions have on their victims. They are the people responsible for this. Just as you wouldn't normally blame a victim of assault or robbery for being assaulted or robbed, let's not fall into the trap of blaming the victim (the NHS) for the atrocious actions of the real culprits: The cyber-criminals.
 
Last edited:

as1981

Member
Joined
26 Apr 2014
Messages
14
Great sympathies for all the people affected by this. It sounds absolutely shocking - already reports of operations being cancelled because of it. Sadly, I guess cyber-crime is so inevitable that it was always going to be only a matter of time before an essential organisation such as the NHS was hit :(

...

However, before we start blaming the NHS, let's be clear that responsibility for this attack almost certainly lies with one group of people, and one group of people only: The criminals who write malware and use it to extort money without any thought for the effect their actions have on their victims. They are the people responsible for this. Just as you wouldn't normally blame a victim of assault or robbery for being assaulted or robbed, let's not fall into the trap of blaming the victim (the NHS) for the atrocious actions of the real culprits: The cyber-criminals.

Absolutely agree.
 

yorksrob

Veteran Member
Joined
6 Aug 2009
Messages
44,356
Location
Yorks
Until the cyber-criminals are punished to an extent that they find it unpaletable to get caught, this sort of thing will become more common.
 

dgl

Established Member
Joined
5 Oct 2014
Messages
3,061
But surely this attack would probably have come from a compromised email attachment so it is probably a user that is ultimately to blame even though the criminals should not be doing this anyway. Plus if it was a compromised attachment the emails are usually (for me at least) easy to spot as it's usually advertised as a .pdf or .doc attachment when it's a program within a zip file.

Annoyingly very few attacks require no user intervention and as such if people were trained correctly then these sort of things may not happen. Just because computers are easier to use than ever it doesn't mean that no training is required or proper IT policy employed.
 

ExRes

Established Member
Joined
16 Dec 2012
Messages
8,368
Location
Back in Sussex
I would have thought it a bit unfair to single out the NHS for blame at this time, the BBC also report that infections have affected in excess of 70 countries including Russia, China, USA, Italy and Spain
 

chris11256

Member
Joined
27 Dec 2012
Messages
741
From what I understand(and as someone that works in IT) the ransomware takes advantage of a bug in Windows XP. This bug has apparently been fixed in newer versions of Windows,.
 

yorksrob

Veteran Member
Joined
6 Aug 2009
Messages
44,356
Location
Yorks
But surely this attack would probably have come from a compromised email attachment so it is probably a user that is ultimately to blame even though the criminals should not be doing this anyway. Plus if it was a compromised attachment the emails are usually (for me at least) easy to spot as it's usually advertised as a .pdf or .doc attachment when it's a program within a zip file.

Annoyingly very few attacks require no user intervention and as such if people were trained correctly then these sort of things may not happen. Just because computers are easier to use than ever it doesn't mean that no training is required or proper IT policy employed.

In any big organisation people open files from emails all the time. They are warned not to open "unexpected" attachments but it is unrealistic to expect no occurrences to happen in organisations of thousands upon thousands of employees.
 

Barn

Established Member
Joined
3 Sep 2008
Messages
1,487
However, before we start blaming the NHS, let's be clear that responsibility for this attack almost certainly lies with one group of people, and one group of people only: The criminals who write malware and use it to extort money without any thought for the effect their actions have on their victims. They are the people responsible for this. Just as you wouldn't normally blame a victim of assault or robbery for being assaulted or robbed, let's not fall into the trap of blaming the victim (the NHS) for the atrocious actions of the real culprits: The cyber-criminals.

Not sure I quite agree. Although you are absolutely correct that the primary blame for this lies with the criminals, the NHS is not just a victim. It is a trustee for our information, our safety and our money. It does have a duty to all of us to follow best IT practice.
 

TheEdge

Established Member
Joined
29 Nov 2012
Messages
4,498
Location
Norwich
I would have thought it a bit unfair to single out the NHS for blame at this time, the BBC also report that infections have affected in excess of 70 countries including Russia, China, USA, Italy and Spain

The BBC did suggest that it is likely these attacks started aimed at companies which have then spread to their clients naturally, in our case the NHS. The point was whoever sent the ransomware out probably expected to fight against the IT department of some company but are now facing off against states.

I assume that the National Cyber Crime Unit is already on the case, and I imagine GCHQ probably wont keep their nose out for too long...
 

PHILIPE

Veteran Member
Joined
14 Nov 2011
Messages
13,472
Location
Caerphilly
From what I understand(and as someone that works in IT) the ransomware takes advantage of a bug in Windows XP. This bug has apparently been fixed in newer versions of Windows,.

Windows XP is no longer supported by Microsoft so I had to upgrade to Windows 7 back in early 2014. Could this have had a bearing on the problem I wonder. Although Wales is apparently not affected, thanks for small mercies, I noticed a particular hospital was still using XP last year.
 

Darandio

Established Member
Joined
24 Feb 2007
Messages
11,141
Location
Redcar
Windows XP is no longer supported by Microsoft so I had to upgrade to Windows 7 back in early 2014. Could this have had a bearing on the problem I wonder. Although Wales is apparently not affected, thanks for small mercies, I noticed a particular hospital was still using XP last year.

Probably.

Although when the 2014 deadline passed, a pretty sum was paid to Microsoft to continue XP support, but this reportedly elapsed in 2015.
 

yorksrob

Veteran Member
Joined
6 Aug 2009
Messages
44,356
Location
Yorks
But then again, when Windows effectively becomes part of the National digital infrastructure, should it be allowed to just decide that it isn't going to support XP for example. Should it face penalties for not upgrading.
 

me123

Established Member
Joined
9 Jul 2007
Messages
8,510
I wonder if underinvestment in IT systems is partly responsible. The NHS uses cheap and out-of-date options which aren't really suitable for a large organisation holding large volumes of sensitive information.

Disagree. Some places are better than others. Some places I've worked have better IT than others. The NHS does not have one big network, so this is a massive attack on multiple systems and it affects different boards/trusts differently. Certainly the main systems used pretty much throughout NHS Scotland are not cheap, and are in fact very sophisticated and actually capable of far more than it's currently used for.

And it's not just the NHS - apparently it's been reported in over 70 countries worldwide.

FWIW, NHS Wales is unaffected at present (aside from some issues communicating with tertiary service providers in Englandshire - probably more a North Wales thing). Betsi Cadwaladr UHB still has Windows XP PCs (not many left, but some) so it doesn't seem to be just an XP thing.
 

Darandio

Established Member
Joined
24 Feb 2007
Messages
11,141
Location
Redcar
Who forked out for this payment ?

The government, at the tune of £5.5m apparently. Read the 19:20 entry on the live page:

http://www.bbc.co.uk/news/live/39901370

Some who have followed the issue of NHS cyber security are sharing a report from the IT news site Silicon, which reported last December that NHS trusts had been running outdated Windows XP software.

The website says that Microsoft officially ended support for Windows XP back in April 2014, meaning it was no longer fixing vulnerabilities in the system - except for clients that paid for an extended support deal.

The UK government initially paid Microsoft £5.5 million to keep providing security support - but the website adds that this deal ended in May 2015.
 

yorksrob

Veteran Member
Joined
6 Aug 2009
Messages
44,356
Location
Yorks
We had power stations before the internet.
We had hospitals before the internet.
We had the national grid before the internet.

Why does everything have to be plugged into the internet ?
 

me123

Established Member
Joined
9 Jul 2007
Messages
8,510
We had power stations before the internet.
We had hospitals before the internet.
We had the national grid before the internet.

Why does everything have to be plugged into the internet ?

Because things generally do work better with the internet.

The internet has made sharing of data between and within hospitals much easier. We no longer rely on fax (in itself, a form of technology that didn't exist) and snail mail. We can share images with specialists in other hospitals. We can discuss said cases over a video link, meaning that people from around the country can give valuable input. We no longer have to rely on paper notes (which are cumbersome) or paper communiqués (which are slow and inefficient). I can get urgent bloods instantaneously on a computer, rather than an hour later when the small piece of paper drops on a desk somewhere. There are back ups, but there's a good reason that the internet is widely used - because it vastly improves our capabilities.
 

Peter Mugridge

Veteran Member
Joined
8 Apr 2010
Messages
17,839
Location
Epsom
But surely this attack would probably have come from a compromised email attachment so it is probably a user that is ultimately to blame even though the criminals should not be doing this anyway. Plus if it was a compromised attachment the emails are usually (for me at least) easy to spot as it's usually advertised as a .pdf or .doc attachment when it's a program within a zip file.

Annoyingly very few attacks require no user intervention and as such if people were trained correctly then these sort of things may not happen. Just because computers are easier to use than ever it doesn't mean that no training is required or proper IT policy employed.

Ransomware has been known to spread through malicious script in advertisements which can be placed even on reputable sites and can activate without even clicking on the advert; a pop up is sufficient; I speak from expensive* experience...



*No, I didn't pay up. Expensive as in a whole new system...
 

yorksrob

Veteran Member
Joined
6 Aug 2009
Messages
44,356
Location
Yorks
Because things generally do work better with the internet.

The internet has made sharing of data between and within hospitals much easier. We no longer rely on fax (in itself, a form of technology that didn't exist) and snail mail. We can share images with specialists in other hospitals. We can discuss said cases over a video link, meaning that people from around the country can give valuable input. We no longer have to rely on paper notes (which are cumbersome) or paper communiqués (which are slow and inefficient). I can get urgent bloods instantaneously on a computer, rather than an hour later when the small piece of paper drops on a desk somewhere. There are back ups, but there's a good reason that the internet is widely used - because it vastly improves our capabilities.

Well, I hope we've got a back-up because the internet is open to everybody, friend and enemy alike.
 

Shaw S Hunter

Established Member
Joined
21 Apr 2016
Messages
3,495
Location
Over The Hill
We had power stations before the internet.
We had hospitals before the internet.
We had the national grid before the internet.

Why does everything have to be plugged into the internet ?

Because things generally do work better with the internet.

The internet has made sharing of data between and within hospitals much easier. We no longer rely on fax (in itself, a form of technology that didn't exist) and snail mail. We can share images with specialists in other hospitals. We can discuss said cases over a video link, meaning that people from around the country can give valuable input. We no longer have to rely on paper notes (which are cumbersome) or paper communiqués (which are slow and inefficient). I can get urgent bloods instantaneously on a computer, rather than an hour later when the small piece of paper drops on a desk somewhere. There are back ups, but there's a good reason that the internet is widely used - because it vastly improves our capabilities.

Well, I hope we've got a back-up because the internet is open to everybody, friend and enemy alike.

It does seem as if there are some decision makers who are so enamoured with the modern concept of connectivity that some things are being connected that actually have no reason to be. Leading to some unexpected consequences. Like the west being able to sabotage Iran's nuclear programme by cyber attack. It would surely be a good idea for government to promote basic "digital education", particularly for older people (like me!) who didn't gain any experience in the use of computers until entering employment. Such education should include all those helpful hints on how to avoid fairly obvious pitfalls, though IME even apparently tech-savvy younger people can be highly complacent about the risks. I suspect many organisations make huge assumptions about the IT capability of many of their employees.
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,682
Location
Scotland
We had power stations before the internet.
We had hospitals before the internet.
We had the national grid before the internet.

Why does everything have to be plugged into the internet ?
If you want to go back to life in the 1970s with all the inefficiencies that go with it then you're welcome to it. I'll stick with the 21st century, thank you very much.
 

sk688

Member
Joined
11 Sep 2016
Messages
847
Location
Dublin
We had power stations before the internet.
We had hospitals before the internet.
We had the national grid before the internet.

Why does everything have to be plugged into the internet ?

The bigger question would be what can you do without the Internet

I certainly can't imagine life without the Internet, being born at the start of the millennium , and indeed now I can't imagine life without it especially on phones, e.g Snapchat, Instagram etc. If there was no Web, we'd have no Google, Netflix, catch up TV, streaming etc

The Internet has had a huge impact on our lives since 1992, and although it has issues , if you use older versions you are at risk of attack ( like what is happening now), it is a brilliant tool, that lots of us love, and can't imagine being without
 
Status
Not open for further replies.

Top