Two major healthcare organisations, Boston Scientific and McKesson, have disclosed cyberattacks that disrupted pacemaker monitoring and exposed millions of patients' data.
Criminals have also been breaking into unpatched PaperCut print servers
A cyberattack on Manchester Airports Group exposed data belonging to 8.7 million customers.
More than twenty critical flaws in Ubiquiti network devices
A serious bug in WatchGuard's own security software.
Maximum-severity flaws just fixed in the ServiceNow platform.
Read on to find out more...
Two major healthcare companies disclosed serious cyberattacks over the weekend. Medical device maker Boston Scientific said a cyberattack that began on 25 August is still ongoing, and that it has stopped some heart devices, including pacemakers and other cardiac monitors implanted since the attack began, from sending data automatically to remote monitoring systems. Patients can still have their device checked in person, but the company has no timeline for full restoration and has hired outside experts to help investigate. Separately, pharmaceutical and medical supply giant McKesson confirmed that attackers broke into some of its cloud systems by tricking staff over the phone, a technique known as voice phishing. The criminal group responsible, known as ShinyHunters, says it stole data on millions of patients, including names, addresses, dates of birth, Social Security numbers (the US equivalent of a National Insurance number) and details of medical conditions, and is demanding a ransom of over $55 million. McKesson has not confirmed exactly how many patients are affected.
These two incidents show that criminals are increasingly targeting healthcare and medical supply companies, and that the damage now goes beyond stolen data. The Boston Scientific attack shows a cyberattack can directly disrupt how patient medical devices are monitored, not just an organisation's paperwork. The McKesson breach shows that a single successful phone call to the right member of staff can be enough to bypass technical security controls entirely. Any NHS supplier, healthtech, or organisation that relies on similar cloud platforms, or that works with medical device manufacturers or pharmaceutical suppliers, should see this as a warning about both device security and staff awareness of voice phishing.
Recommendations:
PaperCut makes software that many organisations, including NHS trusts, GP surgeries and schools, use to manage office printing. Criminals have found two weaknesses in PaperCut's NG and MF products and are using them together to break in. The first lets an attacker with no account change the server's settings. The second then lets them run their own harmful code on the machine. PaperCut has released emergency updates, but attackers moved fast: security researchers say they were testing the attack within days, and at least two real organisations have already been hit. Even PaperCut's first fix could be bypassed, so a second, stronger patch has now been released.
PaperCut is potentially used widely across the NHS and other UK public services to manage printing, and NHS England's own cyber team say further attacks are highly likely. A server that criminals can control could be used to spy on an organisation's network, spread further, or set up a bigger attack such as ransomware. Any NHS supplier or digital health organisation running PaperCut, or that submits an NHS Data Security and Protection Toolkit (DSPT) return, should treat this as an urgent, live risk rather than routine housekeeping.
Recommendations:
Manchester Airports Group, which owns Manchester, Stansted and East Midlands airports, said an unauthorised third party had broken into its systems and stolen data belonging to around 8.7 million customers. The stolen information relates to car park, lounge and Fast Track bookings, and to sign-ups for airport Wi-Fi, and includes email addresses, phone numbers, vehicle registration numbers and postcodes. The company says no bank or payment details were taken, that passenger safety and aviation security were never at risk, and that flights and car parking continued running normally throughout. It says it has contained the incident and is working with specialist advisers and the relevant authorities.
This is one of the largest UK data breaches disclosed this year, and a reminder that criminals continue to target transport and other critical infrastructure, following a cyberattack on European airport check-in systems last year. Although flight safety was not affected, the stolen contact details and vehicle registrations could be used to send convincing follow-up phishing messages to millions of people. It is not a healthcare-specific incident, but any organisation, including NHS suppliers, that collects customer data through third-party booking, parking or Wi-Fi sign-up systems should take note of how quickly and clearly Manchester Airports Group communicated, and review its own arrangements with similar third parties.
Recommendations:
Ubiquiti, a company that makes popular UniFi network equipment such as routers, cameras, and Wi-Fi access points, has released a security bulletin covering 22 separate flaws. Twenty-one of these are rated critical, the highest level of concern. Some of the flaws would let an attacker who can reach the device over a network take control of it without needing a password or any help from a user, for example by sneaking in commands the device was never meant to run.
UniFi devices are popular with small and medium-sized UK businesses, and are sometimes found in clinics, care settings, and NHS supplier offices because they are affordable and easy to manage. A single unpatched device facing the internet could give an attacker a way into an organisation's whole network. There is no confirmed evidence yet that criminals are exploiting these flaws, but the scale and severity mean it is only a matter of time before someone tries.
Recommendations:
WatchGuard Agent, a piece of security software that protects and monitors company computers, has two serious flaws. Together, they could let an attacker who has not logged in and does not need a password run their own commands on an affected machine with the highest level of access. WatchGuard has released updates to fix both issues.
Security software is normally trusted completely and often given wide-reaching access, which is exactly why it is such an attractive target for criminals. If an attacker takes over a security agent, they can potentially hide from the very tool meant to catch them, then quietly move around a network or deploy ransomware. Any organisation using WatchGuard Agent, including smaller digital health suppliers who rely on it for endpoint protection, should treat this as high priority.
Recommendations:
ServiceNow, a cloud platform many large organisations use to manage IT requests, workflows, and increasingly artificial intelligence tools, has fixed four serious flaws. Three of them scored the maximum possible severity rating. The flaws could have let someone with no account at all run their own code, change data they should not be able to touch, or run harmful database commands, all without tricking a single member of staff. ServiceNow says it has fixed its hosted instances and provided updates to partners and self-hosted customers, and it is not currently aware of the flaws being used in real attacks.
ServiceNow is used by a wide range of UK organisations, including NHS suppliers and healthtechs, to run internal processes and, increasingly, AI-powered tools. A flaw this severe in a platform so many businesses rely on is a reminder of how much trust is placed in cloud providers. Even though no known attacks have happened yet, and ServiceNow has already deployed fixes centrally, organisations should still confirm they are protected rather than assume nothing needs to be done.
Recommendations:
Want help staying ahead of threats like these? Contact Periculo about our Threat Intelligence services and find out how we support UK digital health organisations, healthtechs, and NHS suppliers with practical, hands-on cybersecurity assurance.