Threat Report 190
Two major healthcare organisations, Boston Scientific and McKesson, have disclosed cyberattacks that disrupted pacemaker monitoring and exposed millions of patients' data.
Criminals have also been breaking into unpatched PaperCut print servers
A cyberattack on Manchester Airports Group exposed data belonging to 8.7 million customers.
More than twenty critical flaws in Ubiquiti network devices
A serious bug in WatchGuard's own security software.
Maximum-severity flaws just fixed in the ServiceNow platform.
Read on to find out more...
Cyberattacks Disrupt Pacemakers and Expose Millions of Patient Records
Two major healthcare companies disclosed serious cyberattacks over the weekend. Medical device maker Boston Scientific said a cyberattack that began on 25 August is still ongoing, and that it has stopped some heart devices, including pacemakers and other cardiac monitors implanted since the attack began, from sending data automatically to remote monitoring systems. Patients can still have their device checked in person, but the company has no timeline for full restoration and has hired outside experts to help investigate. Separately, pharmaceutical and medical supply giant McKesson confirmed that attackers broke into some of its cloud systems by tricking staff over the phone, a technique known as voice phishing. The criminal group responsible, known as ShinyHunters, says it stole data on millions of patients, including names, addresses, dates of birth, Social Security numbers (the US equivalent of a National Insurance number) and details of medical conditions, and is demanding a ransom of over $55 million. McKesson has not confirmed exactly how many patients are affected.
These two incidents show that criminals are increasingly targeting healthcare and medical supply companies, and that the damage now goes beyond stolen data. The Boston Scientific attack shows a cyberattack can directly disrupt how patient medical devices are monitored, not just an organisation's paperwork. The McKesson breach shows that a single successful phone call to the right member of staff can be enough to bypass technical security controls entirely. Any NHS supplier, healthtech, or organisation that relies on similar cloud platforms, or that works with medical device manufacturers or pharmaceutical suppliers, should see this as a warning about both device security and staff awareness of voice phishing.
Recommendations:
- Check whether your organisation uses Boston Scientific devices or McKesson's supply or data services, and ask them directly for an update if so.
- Train staff who can access cloud platforms such as Salesforce or Snowflake to recognise and challenge unexpected phone calls asking them to reset passwords or grant access.
- Require call-back verification through a known, trusted number before acting on any phone request to change account access.
- Use multi-factor authentication on all cloud business systems, and review which staff genuinely need access to sensitive customer or patient data.
- Treat ransom demands and criminal claims about how much data was stolen with caution; wait for official confirmation before reacting.
- Record your organisation's exposure and response to this incident for your risk register or DSPT evidence if relevant.
Criminals Are Breaking Into PaperCut Print Software Right Now
PaperCut makes software that many organisations, including NHS trusts, GP surgeries and schools, use to manage office printing. Criminals have found two weaknesses in PaperCut's NG and MF products and are using them together to break in. The first lets an attacker with no account change the server's settings. The second then lets them run their own harmful code on the machine. PaperCut has released emergency updates, but attackers moved fast: security researchers say they were testing the attack within days, and at least two real organisations have already been hit. Even PaperCut's first fix could be bypassed, so a second, stronger patch has now been released.
PaperCut is potentially used widely across the NHS and other UK public services to manage printing, and NHS England's own cyber team say further attacks are highly likely. A server that criminals can control could be used to spy on an organisation's network, spread further, or set up a bigger attack such as ransomware. Any NHS supplier or digital health organisation running PaperCut, or that submits an NHS Data Security and Protection Toolkit (DSPT) return, should treat this as an urgent, live risk rather than routine housekeeping.
Recommendations:
- Check whether your organisation, or any IT provider you use, runs PaperCut NG or PaperCut MF.
- Install PaperCut's Emergency Patch Release 2 immediately; the first patch alone is not enough.
- If you cannot patch straight away, block public internet access to your PaperCut server and only allow trusted internal addresses.
- Look for the indicators of compromise PaperCut has published, including unexpected log file deletions.
- Ask your IT provider to confirm in writing that patching is complete, and record this for your DSPT evidence.
- Report any suspected compromise to the NHS England Cyber Security Operations Centre on 0300 303 5222 or cybersecurity@nhs.net.
Data Stolen From 8.7 Million Customers in Cyberattack on Three UK Airports
Manchester Airports Group, which owns Manchester, Stansted and East Midlands airports, said an unauthorised third party had broken into its systems and stolen data belonging to around 8.7 million customers. The stolen information relates to car park, lounge and Fast Track bookings, and to sign-ups for airport Wi-Fi, and includes email addresses, phone numbers, vehicle registration numbers and postcodes. The company says no bank or payment details were taken, that passenger safety and aviation security were never at risk, and that flights and car parking continued running normally throughout. It says it has contained the incident and is working with specialist advisers and the relevant authorities.
This is one of the largest UK data breaches disclosed this year, and a reminder that criminals continue to target transport and other critical infrastructure, following a cyberattack on European airport check-in systems last year. Although flight safety was not affected, the stolen contact details and vehicle registrations could be used to send convincing follow-up phishing messages to millions of people. It is not a healthcare-specific incident, but any organisation, including NHS suppliers, that collects customer data through third-party booking, parking or Wi-Fi sign-up systems should take note of how quickly and clearly Manchester Airports Group communicated, and review its own arrangements with similar third parties.
Recommendations:
- If you have booked parking, a lounge, or Fast Track, or used the Wi-Fi at Manchester, Stansted or East Midlands airports, be alert to phishing emails or texts referencing these services.
- Do not click links in unexpected messages claiming to be from these airports; go directly to the official website instead.
- Review any contracts with third parties who collect customer data on your behalf, including their breach notification obligations.
- Make sure your own incident response plan includes prompt notification to the Information Commissioner's Office, in line with what Manchester Airports Group appears to have done.
- Remind customers and staff that legitimate airport communications will not ask for banking details, especially following a breach like this.
Over 20 Serious Flaws Found in Popular Ubiquiti Network Devices
Ubiquiti, a company that makes popular UniFi network equipment such as routers, cameras, and Wi-Fi access points, has released a security bulletin covering 22 separate flaws. Twenty-one of these are rated critical, the highest level of concern. Some of the flaws would let an attacker who can reach the device over a network take control of it without needing a password or any help from a user, for example by sneaking in commands the device was never meant to run.
UniFi devices are popular with small and medium-sized UK businesses, and are sometimes found in clinics, care settings, and NHS supplier offices because they are affordable and easy to manage. A single unpatched device facing the internet could give an attacker a way into an organisation's whole network. There is no confirmed evidence yet that criminals are exploiting these flaws, but the scale and severity mean it is only a matter of time before someone tries.
Recommendations:
- Identify any UniFi Protect, Network, Access, Talk, or Connect devices, or UniFi OS systems, in your organisation.
- Apply Ubiquiti's updates from Security Advisory Bulletin 067 as soon as possible.
- Make sure UniFi management interfaces are not reachable from the public internet.
- Ask any IT provider who manages your network equipment to confirm they have patched.
- Include network hardware, not just servers and laptops, in your regular vulnerability management checks.
A Popular Security Tool Itself Has a Serious Flaw
WatchGuard Agent, a piece of security software that protects and monitors company computers, has two serious flaws. Together, they could let an attacker who has not logged in and does not need a password run their own commands on an affected machine with the highest level of access. WatchGuard has released updates to fix both issues.
Security software is normally trusted completely and often given wide-reaching access, which is exactly why it is such an attractive target for criminals. If an attacker takes over a security agent, they can potentially hide from the very tool meant to catch them, then quietly move around a network or deploy ransomware. Any organisation using WatchGuard Agent, including smaller digital health suppliers who rely on it for endpoint protection, should treat this as high priority.
Recommendations:
- Check whether your organisation uses WatchGuard Agent and identify the version in use.
- Update to version 1.25.13.0000 or later as soon as possible.
- Ask your IT provider or managed security service to confirm patching has been completed.
- Review endpoint and security tool logs for any unusual activity around the affected period.
- Treat security software as part of your critical infrastructure when planning patch priorities, not an afterthought.
Maximum-Severity Flaws Fixed in Widely Used ServiceNow Platform
ServiceNow, a cloud platform many large organisations use to manage IT requests, workflows, and increasingly artificial intelligence tools, has fixed four serious flaws. Three of them scored the maximum possible severity rating. The flaws could have let someone with no account at all run their own code, change data they should not be able to touch, or run harmful database commands, all without tricking a single member of staff. ServiceNow says it has fixed its hosted instances and provided updates to partners and self-hosted customers, and it is not currently aware of the flaws being used in real attacks.
ServiceNow is used by a wide range of UK organisations, including NHS suppliers and healthtechs, to run internal processes and, increasingly, AI-powered tools. A flaw this severe in a platform so many businesses rely on is a reminder of how much trust is placed in cloud providers. Even though no known attacks have happened yet, and ServiceNow has already deployed fixes centrally, organisations should still confirm they are protected rather than assume nothing needs to be done.
Recommendations:
- Confirm with your ServiceNow administrator, or your provider, that instances are on a patched version referenced in KB3152242.
- Ask whether any self-hosted or partner-managed ServiceNow instances still need the update applying manually.
- Review ServiceNow access logs for unusual activity, particularly around AI platform features.
- Keep a record of this advisory and your organisation's response for your risk register or DSPT evidence.
- Subscribe to ServiceNow's security bulletins so future issues are caught quickly.
Want Help Staying Ahead of Threats Like These?
Want help staying ahead of threats like these? Contact Periculo about our Threat Intelligence services and find out how we support UK digital health organisations, healthtechs, and NHS suppliers with practical, hands-on cybersecurity assurance.