{"id":14876,"date":"2019-03-19T08:10:05","date_gmt":"2019-03-19T16:10:05","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/03\/19\/news-8625\/"},"modified":"2019-03-19T08:10:05","modified_gmt":"2019-03-19T16:10:05","slug":"news-8625","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/03\/19\/news-8625\/","title":{"rendered":"New research finds hospitals are easy targets for phishing attacks"},"content":{"rendered":"<p><strong>Credit to Author: Joan Goodchild| Date: Tue, 19 Mar 2019 15:00:00 +0000<\/strong><\/p>\n<p>New research from Brigham and Women\u2019s Hospital in Boston finds hospital employees are extremely vulnerable to phishing attacks. The <a href=\"https:\/\/jamanetwork.com\/journals\/jamanetworkopen\/fullarticle\/2727270\" target=\"_blank\" rel=\"noopener\">study<\/a>\u00a0highlights just how effective phishing remains as a tactic\u2014the need for defense against and awareness of email scams is more critical than ever.<\/p>\n<p>The research was a multi-center exercise that looked at results of phishing simulations at six anonymous healthcare facilities in the US. Research coordinators ran phishing simulations for close to seven years and analyzed click rates for more than 2.9 million simulated emails.\u00a0Results revealed that 422,052 (14.2 percent) of phishing emails were clicked, which is a rate of one in seven.<\/p>\n<h3>Patient data at risk<\/h3>\n<p>Security professionals are acutely aware of the intense scrutiny placed on patient data and the regulatory requirements around HIPAA\u00a0(Health Insurance Portability and Accountability Act). This new research on phishing in healthcare puts a spotlight on the vulnerability of this kind of data.<\/p>\n<p>\u201cPatient data, patient care, patient trust and financial stability may be on the line,\u201d said study author William Gordon, MD, MBI, of the Brigham\u2019s Division of General Internal Medicine and Primary Care. \u201cUnderstanding susceptibility, but also what steps can be taken to mitigate it, are critical as cyberattacks continue to rise.\u201d<\/p>\n<h3>Odds of clicks decreased with time<\/h3>\n<p>There was a positive finding in the study. Researchers noted that clicks on phishing emails went down with increasing campaigns. After institutions had run 10 or more phishing simulation campaigns, the odds of users clicking on fraudulent emails went down by more than one-third.<\/p>\n<p>The findings make the case for solid awareness efforts to educate about the dangers of phishing, said Gordon.<\/p>\n<p>&#8220;Things get better over time with awareness, education, and training,\u201d he said. \u201cOur study suggests that while the risk is high, there is an opportunity to mitigate it.\u201d<\/p>\n<h3>Healthcare industry struggles with breach rate<\/h3>\n<p>Chris Carmody, senior vice president of enterprise technology and services at the University of Pittsburgh Medical Center (UPMC) and president of Clinical Connect Health Information Exchange, noted in an interview with <a href=\"https:\/\/whtc.com\/news\/articles\/2019\/mar\/08\/healthcare-organizations-are-battling-phishing\/\" target=\"_blank\" rel=\"noopener\">Reuters Health News<\/a> that phishing is a challenge in an increasingly digital healthcare environment.<\/p>\n<p>&#8220;This is definitely a problem in all industries where people rely on e-communications, especially email,&#8221; Carmody said in the interview. &#8220;And health care is no different. We see clinical users whose primary focus is on patient care, and we&#8217;re trying to do our best to help them develop the knowhow to know what to look for so they can identify phishing attempts and report them to us.&#8221;<\/p>\n<p>Carmody estimates that his security group at UMPC, which also runs phishing simulations, gets about 7,500 suspect emails forwarded to them each month, with about 12.5 percent of them being actually malicious.<\/p>\n<p>But any number puts a healthcare facility at risk, as these kinds of institutions are particularly vulnerable to breach. A separate report from <a href=\"https:\/\/www.cisomag.com\/us-healthcare-institutions-are-vulnerable-to-phishing-attacks-survey\/\" target=\"_blank\" rel=\"noopener\">Beazley Breach Response<\/a> finds that healthcare organizations suffered the highest number of data breaches in 2018 across any sector of the US economy. Healthcare institutions have a 41 percent reported breach rate, the highest of any industry.<\/p>\n<p>Other figures from ratings firm SecurityScorecard find the healthcare industry is one of the lowest ranked industries when it comes to security practices. <a href=\"https:\/\/www.prnewswire.com\/news-releases\/report-reveals-healthcare-organizations-are-deathly-behind-on-patching-cadence-300598375.html\" target=\"_blank\" rel=\"noopener\">The report<\/a>, titled <em>SecurityScorecard 2018 Healthcare Report: A Pulse on The Healthcare Industry\u2019s Cybersecurity Risk<\/em>, looked at data from 1200 healthcare entities and ranked healthcare 15<sup>th<\/sup> out of 17 industries for overall cybersecurity posture.<\/p>\n<p>The SecurityScorecard report noted the healthcare industry is one of the lowest performing industries in terms of endpoint security, posing a threat to patient data and potentially patient lives. In addition, 60 percent of the most common cybersecurity issues in the healthcare industry relate to poor patching cadence.<\/p>\n<h3>Healthcare phishing in the headlines<\/h3>\n<p>Healthcare phishing attempts that devastate facilities and lead to patient data leaks regularly make news headlines. In December 2018, an employee of\u00a0<a href=\"http:\/\/www.gulfportmemorial.com\/Uploads\/Public\/Documents\/MHG%20Substitute%20Notice.pdf\" target=\"_blank\" rel=\"noopener\">Memorial Hospital<\/a>\u00a0at Gulfport, Mississippi was tricked by a phishing scheme and the result was the breached data of 30,000 patients.<\/p>\n<p>The breach was discovered when investigators noticed an unauthorized party had gained access to an employee email account earlier in the month. Among the patient data leaked were emails, names, dates of birth, health data, and information about services patients had received at MHG. Social Security numbers were also leaked on some patients.<\/p>\n<h3>Phishing on the rise all over<\/h3>\n<p>Massive malware campaigns like Emotet and TrickBot have pushed phishing levels higher this year in many industries. Kaspersky Labs most recent <a href=\"https:\/\/securelist.com\/spam-and-phishing-in-2018\/89701\/\" target=\"_blank\" rel=\"noopener\">Spam and phishing in 2018<\/a>\u00a0report finds the number of phishing attacks that took place in 2018 more than doubled from the previous year.<\/p>\n<p>Research from Sophos finds that 45 percent of UK businesses were hit by phishing attacks between 2016 and 2018. The study also revealed 54 percent had identified instances of employees replying to unsolicited emails or clicking the links in them.<\/p>\n<p>The Malwarebytes\u00a0<a href=\"https:\/\/blog.malwarebytes.com\/malwarebytes-news\/2019\/01\/2019-state-malware-report-trojans-cryptominers-dominate-threat-landscape\/\" target=\"_blank\" rel=\"noopener\">2019 State of Malware report<\/a>\u00a0finds all sectors are impacted by the kind of malware served up in phishing emails. Trojans like Emotet and TrickBot are particularly problematic in education, manufacturing, and retail. While healthcare fared poorly in the Brigham and Women\u2019s study, every vertical is plagued by phishing.<\/p>\n<h3>How can business defend against phishing attacks?<\/h3>\n<p>Of all of the cybersecurity risks to organizations, the human element is always the toughest to mitigate. But, as the healthcare phishing study shows, user awareness does have a positive impact on click rates\u2014the more campaigns were launched, the fewer employees who fell prey to fake emails.<\/p>\n<p>There are plenty of free awareness and anti-phishing resources available that businesses can tap for training internally. For example, our <a href=\"https:\/\/blog.malwarebytes.com\/101\/2019\/02\/business-anti-phishing\/\" target=\"_blank\" rel=\"noopener\">anti-phishing guide<\/a> offers suggestions and awareness tips for both employees and customers. And Google has an\u00a0<a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/43zgmw\/google-jigsaw-phishing-quiz\" target=\"_blank\" rel=\"noopener\">anti-phishing test<\/a> you can access online to familiarize users with common phishing techniques. Of course, there are also many companies that offer training products for purchase.<\/p>\n<p>However businesses choose to train employees, it\u2019s important to have regular access to information and tools that promote awareness of evolving phishing techniques. In the healthcare industry, it\u2019s not just about the bottom line\u2014it could actually save lives.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/101\/2019\/03\/new-research-finds-hospitals-are-easy-targets-for-phishing-attacks\/\">New research finds hospitals are easy targets for phishing attacks<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/101\/2019\/03\/new-research-finds-hospitals-are-easy-targets-for-phishing-attacks\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Joan Goodchild| Date: Tue, 19 Mar 2019 15:00:00 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/101\/2019\/03\/new-research-finds-hospitals-are-easy-targets-for-phishing-attacks\/' title='New research finds hospitals are easy targets for phishing attacks'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/03\/shutterstock_1011376669.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>New research from Brigham and Women\u2019s Hospital in Boston finds hospital employees are extremely vulnerable to phishing attacks. The study\u00a0highlights just how effective phishing remains as a tactic, and why awareness of email scams is more critical than ever.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/101\/\" rel=\"category tag\">101<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/101\/business\/\" rel=\"category tag\">Business<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/anti-phishing\/\" rel=\"tag\">anti-phishing<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/healthcare\/\" rel=\"tag\">healthcare<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/healthcare-cybersecurity\/\" rel=\"tag\">healthcare cybersecurity<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/hospital-security\/\" rel=\"tag\">hospital security<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/hospitals\/\" rel=\"tag\">hospitals<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/phishing\/\" rel=\"tag\">phishing<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/101\/2019\/03\/new-research-finds-hospitals-are-easy-targets-for-phishing-attacks\/' title='New research finds hospitals are easy targets for phishing attacks'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/101\/2019\/03\/new-research-finds-hospitals-are-easy-targets-for-phishing-attacks\/\">New research finds hospitals are easy targets for phishing attacks<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10519,18778,1001,5976,17547,21296,7370,3924],"class_list":["post-14876","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-10519","tag-anti-phishing","tag-business","tag-healthcare","tag-healthcare-cybersecurity","tag-hospital-security","tag-hospitals","tag-phishing"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14876","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=14876"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14876\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=14876"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=14876"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=14876"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}