{"id":9708,"date":"2017-10-05T06:45:14","date_gmt":"2017-10-05T14:45:14","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/10\/05\/news-3481\/"},"modified":"2017-10-05T06:45:14","modified_gmt":"2017-10-05T14:45:14","slug":"news-3481","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/10\/05\/news-3481\/","title":{"rendered":"Cyberattacks Against Abortion Clinics Have Increased At an Alarming Rate"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/59d42f47f9bd7c75032230fb\/master\/pass\/Abortion_Cyberhacks-01-FA.jpg\"\/><\/p>\n<p><strong>Credit to Author: Rebecca Grant| Date: Thu, 05 Oct 2017 12:00:00 +0000<\/strong><\/p>\n<p data-reactid=\"248\"><span class=\"lede\" data-reactid=\"249\">Fatimah Gifford was <\/span><!-- react-text: 250 -->nervous the day she was scheduled to testify in front of Texas\u2019 Health and Human Services committee. Gifford is the VP of Communications for Whole Woman\u2019s Health, which operates five reproductive healthcare clinics across Texas. This wasn\u2019t her first time testifying before the state legislature, but it was her first time testifying about abortion.<!-- \/react-text --><\/p>\n<p data-reactid=\"251\">\u201cI entered into this with eyes wide open, and knowing that I was more than likely going to be devoured up in there,\u201d she says.<\/p>\n<p data-reactid=\"252\">Given her job, Gifford is no stranger to high-pressure environments, but she was unprepared for what came next. She slowly walked to the podium, introduced herself, and read her testimony against House Bill 2, a sweeping piece of legislation that laid out some of the harshest abortion restrictions in the country.<\/p>\n<p data-reactid=\"253\"><!-- react-text: 254 -->When she finished, a committee member laid into her. He denounced her for marketing and promoting abortion, and criticized the organization\u2019s website for its professional appearance because it helped \u201csell\u201d abortions. He also read the organization\u2019s URL\u2014 <!-- \/react-text --><a href=\"http:\/\/www.wholewomanshealth.com\/\" target=\"_blank\" data-reactid=\"255\">www.wholewomanshealth.com<\/a><!-- react-text: 256 -->\u2014out loud.<!-- \/react-text --><\/p>\n<p data-reactid=\"259\">\u201cIt was like he mockingly invited people to go to our site and mess with us and made sure our web address made it into public record,\u201d says Amy Hagstrom Miller, the founder and CEO of Whole Woman\u2019s Health. Which is precisely what happened.<\/p>\n<p data-reactid=\"260\">Later that day, Whole Woman\u2019s Health noticed a surge in hacking attempts through routine monitoring of web activity. A few days after, the staff couldn\u2019t log into the website. One of the intrusive efforts had succeeded, and shut the website down for a week.<\/p>\n<p data-reactid=\"261\">It was just the beginning of the onslaught of cyberattacks that Whole Woman\u2019s Health would experience between June 2013 and April 2016, as the organization continued to fight a legal battle over abortion that went all the way to the Supreme Court.<\/p>\n<p data-reactid=\"262\"><!-- react-text: 263 -->The battle lines around abortion in the US have been clearly drawn for decades. Protesters, ranging from handfuls to hundreds, stake territory outside clinics to pray, wave signs, and yell into loudspeakers. On the legislative front, politicians have enacted hundreds of <!-- \/react-text --><a href=\"https:\/\/www.reproductiverights.org\/project\/targeted-regulation-of-abortion-providers-trap\" target=\"_blank\" data-reactid=\"264\">Targeted Restrictions of Abortion Providers<\/a><!-- react-text: 265 --> laws since 2010 that make it difficult for women to access abortion care, and cause clinics to close down.<!-- \/react-text --><\/p>\n<p data-reactid=\"266\">Over the past few years, though, a new front has emerged that many reproductive healthcare organizations struggle to deal with. Cyberattacks and threats, as well as internet harassment, have escalated, aiming to disrupt services, intimidate providers and patients, and prevent women from getting the care they need.<\/p>\n<p data-reactid=\"268\"><span class=\"lede\" data-reactid=\"269\">After the initial <\/span><!-- react-text: 270 -->attack, Whole Woman\u2019s Health hired a cybersecurity specialist to remove the malware and repair the damage that had been done. Still, Hagstrom Miller says, the site suffered more than 500 hacking attempts each day in the wake of Gifford\u2019s testimony. About a month later, hackers found and exploited a vulnerability in the Whole Woman\u2019s Health blog, which gave them a backdoor to the entire website.<!-- \/react-text --><\/p>\n<p data-reactid=\"271\">The second successful attack shut down the site for a month. Without it, potential patients were unable to find the clinics, make appointments, identify hours, locations, and services provided, and ask questions.<\/p>\n<p data-reactid=\"272\">\u201cThe damage was awful,\u201d Gifford said. \u201cOur phones literally stopped ringing. It was devastating. Most of our patients find us online, so with no website and no Google advertising, it made day-to-day awareness nearly impossible.\u201d<\/p>\n<p data-reactid=\"273\">After that attack, Whole Woman\u2019s Health switched to a more secure hosting provider, and rebuilt every single page on its website, around 100 in all. These measures allowed the organization to better track the cyberthreats as they came in, but didn\u2019t stop them. As Whole Woman\u2019s Health continued to speak out in support of abortion rights, hackers continued to strike.<\/p>\n<p data-reactid=\"276\">&#x27;The damage was awful. Our phones literally stopped ringing. It was devastating.&#x27;<\/p>\n<p name=\"inset-left\" class=\"inset-left-component__el\" data-reactid=\"277\">\u2014 Amy Hagstrom Miller, Whole Women&#x27;s Health<\/p>\n<p data-reactid=\"278\"><!-- react-text: 279 -->On April 2, 2014, the <!-- \/react-text --><a href=\"https:\/\/www.reproductiverights.org\/case\/whole-womans-health-v-hellerstedt\" target=\"_blank\" data-reactid=\"280\">Center for Reproductive Rights<\/a><!-- react-text: 281 --> filed a lawsuit on behalf of five Texas clinics challenging HB2, and Whole Woman\u2019s Health became the lead plaintiff. The case wound its way through the lower courts until the Supreme Court issued its decision in 2016. Throughout this multi-year process, Hagstrom Miller emerged as an outspoken advocate for reproductive rights. Every time she went on MSNBC or CNN to talk about the case, Whole Woman\u2019s Health experienced a surge in hacking attempts. In one subsequent attack, hackers rerouted visitors to Whole Woman\u2019s Health website to a pornographic page.<!-- \/react-text --><\/p>\n<p data-reactid=\"282\">\u201cIt was not only not a landing page, but it took you somewhere awful,\u201d Hagstrom Miller said. \u201cI remember being mortified.\u201d<\/p>\n<p data-reactid=\"284\"><span class=\"lede\" data-reactid=\"285\">The high-profile of <\/span><!-- react-text: 286 -->Whole Woman\u2019s Health may have made the organization a unique target, but anti-abortion cyber warfare is part of a larger trend. While hate speech and online harassment have long plagued abortion providers\u2014including over 42,500 incidents of hate speech in 2016 alone, <!-- \/react-text --><a href=\"https:\/\/5aa1b2xfmfh2e2mk03kk8rsx-wpengine.netdna-ssl.com\/wp-content\/uploads\/2016-NAF-Violence-and-Disruption-Statistics.pdf\" target=\"_blank\" data-reactid=\"287\">according to<\/a><!-- react-text: 288 --> the National Abortion Federation\u2014actual hacking represents a serious escalation. Even organizations like Planned Parenthood, which have significant resources and manpower, struggle to prevent attacks from a loosely organized but determined group of \u201chacktivists\u201d and extremists.<!-- \/react-text --><\/p>\n<p data-reactid=\"289\"><!-- react-text: 290 -->In July 2015, <!-- \/react-text --><a href=\"https:\/\/www.wired.com\/2015\/07\/planned-parenthoods-website-apparently-attack\/\" data-reactid=\"291\">Planned Parenthood\u2019s website was hacked<\/a><!-- react-text: 292 --> shortly after the Center for Medical Progress, an anti-abortion group, released secretly recorded (and discredited) videos doctored to make it seem like Planned Parenthood sold fetal tissue. The same attack also targeted the National Network of Abortion Funds and the Abortion Care Network.<!-- \/react-text --><\/p>\n<p data-reactid=\"293\"><a href=\"https:\/\/www.dailydot.com\/layer8\/planned-parenthood-hacked-anti-abortion-3301\/\" target=\"_blank\" data-reactid=\"294\">As reported by the Daily Dot<\/a><!-- react-text: 295 -->, a group called 3301 claimed credit for the hack, and said they used a Blind SQL injection, in which an attacker queries a database in hopes that the response will reveal information or vulnerabilities.<!-- \/react-text --><\/p>\n<p data-reactid=\"296\"><!-- react-text: 297 -->&quot;Here we are, the social justice warriors, seeking to reclaim some sort of lulz for the years and thousands of dollars that Planned Parenthood have wasted and made harvesting your babies,&quot; 3301 wrote on its site. The group then <!-- \/react-text --><a href=\"http:\/\/www.latimes.com\/business\/la-fi-planned-parenthood-hacked-20150727-story.html\" target=\"_blank\" data-reactid=\"298\">published the names and contact information<\/a><!-- react-text: 299 --> for more than 300 Planned Parenthood employees online.<!-- \/react-text --><\/p>\n<p data-reactid=\"300\"><!-- react-text: 301 -->These types of leaks can create real-world danger. Abortion providers have a long history of being <!-- \/react-text --><a href=\"https:\/\/prochoice.org\/education-and-advocacy\/violence\/violence-statistics-and-history\/\" target=\"_blank\" data-reactid=\"302\">stalked, assaulted, harassed, and murdered<\/a><!-- react-text: 303 -->. In communities that are hostile to abortion, it\u2019s not uncommon for staff to hide what they do, drive different routes to work, and take great pains to hide their identity. Doxxing can put their lives at risk.<!-- \/react-text --><\/p>\n<p data-reactid=\"304\"><!-- react-text: 305 -->David Cohen, a professor of law at Drexel University and the <!-- \/react-text --><a href=\"http:\/\/www.livinginthecrosshairs.com\/\" target=\"_blank\" data-reactid=\"306\"><!-- react-text: 307 -->author of <!-- \/react-text --><em data-reactid=\"308\">Living in the Crosshairs: The Untold Stories of Anti-Abortion Terrorism<\/em><!-- react-text: 309 -->,<!-- \/react-text --><\/a><!-- react-text: 310 --> says extremist anti-abortion groups have used tactics like this since the early days of the internet, but the vulnerability landscape has broadened and diversified. Now, for example, the risk of data breaches (which enable doxxing) is greater. According to the <!-- \/react-text --><a href=\"https:\/\/www.feminist.org\/anti...violence\/...\/2016-national-clinic-violence-survey.pdf\" target=\"_blank\" data-reactid=\"311\">2016 National Clinic Violence Survey<\/a><!-- react-text: 312 -->, published by the Feminist Majority Foundation, 13.9 percent of clinics reported that information and pictures of doctors were posted on the internet.<!-- \/react-text --><\/p>\n<p data-reactid=\"313\">\u201cThe antis have been using every tool at their disposal to go after abortion providers and clinics for as long as they have been doing this,\u201d says Cohen. \u201cA lot of clinics did not have a website before five or ten years ago, so the antis were not going to hack anything because there was not anything to hack. As technology spreads and becomes more sophisticated, we are seeing attacks from every angle.\u201d<\/p>\n<p data-reactid=\"315\"><span class=\"lede\" data-reactid=\"316\">Hackers targeted Whole <\/span><!-- react-text: 317 -->Woman\u2019s Health and Planned Parenthood because they are prominent, nationally recognized organizations that advocate for abortion rights, but the threats can be localized as well. Calla Hales is the administrator of A Preferred Women\u2019s Health Center (APWHC), which operates four abortion clinics in North Carolina and Georgia. The Charlotte location attracts protesters that can number in the hundreds every week, and Hales said they are besieged by hacking attempts as well. APWHC recently experienced a DDoS attack that shut down the company\u2019s internet and phones. Hackers have shut down the website on multiple occasions as well.<!-- \/react-text --><\/p>\n<p data-reactid=\"318\">\u201cIt happens pretty regularly and we have had to spend way too much money to fix it,\u201d Hales says. \u201cTo be honest, I\u2019m surprised by how tech-savvy they are.\u201d<\/p>\n<p data-reactid=\"319\">But Craig Petronella, a cybersecurity expert who focuses on the healthcare industry, says that it\u2019s relatively easy these days for any \u201cmotivated group\u201d to wage a cyberattack, whether it\u2019s through malware, ransomware, a phishing scheme, or a DDoS attack.<\/p>\n<p data-reactid=\"320\">\u201cAnyone that knows how to type a word document or a simple email can go on the dark web with malicious intent to find what they are after,\u201d Petronella says. \u201cThe simplicity of it is scary.\u201d<\/p>\n<p data-reactid=\"323\">Organizations without strong protections in place face proportionally greater risk. Many hospitals, clinics, and private practices operate on older technology and equipment and have limited resources to devote to state-of-the-art IT.<\/p>\n<p data-reactid=\"326\">\u201cHealthcare is such low-hanging fruit,\u201d Petronella says. \u201cHackers know their defenses are weak and they are limited on budget, without a lot of sophistication with cybersecurity. They also know that a healthcare practice needs their computer systems and are sensitive to downtime. They can do a lot of damage.\u201d<\/p>\n<p data-reactid=\"327\">Providing abortion services further adds to a clinic\u2019s lure as a target, and because the attacks happen online, people can participate anonymously and from afar. Hales and Hagstrom Miller may recognize the protesters who show up outside their clinics everyday, but they have no idea where the cyberattacks are coming from.<\/p>\n<p data-reactid=\"328\">There are also rules in place for dealing with human protesters that don\u2019t carry over to online interference. The FACE Act prohibits people from trespassing on clinic property and blockading entrances, and law enforcement is supposed to intervene when protesters violate those laws. It\u2019s easier to catch someone who breaks in and physically smashes equipment than a hacker who shuts down a system remotely. Cyberattacks are illegal, but notoriously difficult to police.<\/p>\n<p data-reactid=\"331\">&#x27;As technology spreads and becomes more sophisticated, we are seeing attacks from every angle.&#x27;<\/p>\n<p name=\"inset-left\" class=\"inset-left-component__el\" data-reactid=\"332\">\u2014 David Cohen, Drexel University<\/p>\n<p data-reactid=\"333\">And then there are the threats that exist in gray area. APWHC does not have Wi-Fi, because they ask their patients to stay off their phones for privacy purposes. Hales said one local anti-abortion group sends over a van that parks outside the clinic with a Wi-Fi node that broadcasts a network called Abortion Info. When patients connect to the network, they are taken to a website that looks like APWHC\u2019s, but isn\u2019t.<\/p>\n<p data-reactid=\"334\">\u201cPeople automatically log in and the website looks exactly like our website,\u201d Hales says. \u201cIt has all these cartoon videos that say things like \u2018I\u2019m going to stick in the speculum and rip the arm off.\u2019 It\u2019s creepy as shit.\u201d<\/p>\n<p data-reactid=\"335\"><!-- react-text: 336 -->Geotargeting is another example. In 2016, a mobile advertising and marketing firm called Copley Advertising was hired by RealOptions, a network of crisis pregnancy centers (CPCs), and the evangelical adoption agency Bethany Christian Services, <!-- \/react-text --><a href=\"https:\/\/rewire.news\/article\/2016\/05\/25\/anti-choice-groups-deploy-smartphone-surveillance-target-abortion-minded-women-clinic-visits\/\" target=\"_blank\" data-reactid=\"337\">to target \u201cabortion-minded\u201d women<\/a><!-- react-text: 338 --> in Planned Parenthood clinics with anti-choice messages. Beyond the nuisance factor, the action raises legitimate concerns about anti-choice groups gaining access to personal information about patients, and sending them unwanted messages.<!-- \/react-text --><\/p>\n<p data-reactid=\"339\"><a href=\"http:\/\/boston.cbslocal.com\/2017\/04\/04\/geo-fencing-copley-advertising-massachusetts-health-clincs-abortion\/\" target=\"_blank\" data-reactid=\"340\">Massachusetts recently banned this practice<\/a><!-- react-text: 341 -->, but it demonstrates how the anti-abortion movement has embraced digital tools can to circumvent barriers they face in the physical world. They may not be allowed to walk into a clinic and hand out pamphlets, but they can distribute the same information to the same women in the same place, via their phones.<!-- \/react-text --><\/p>\n<p data-reactid=\"343\"><span class=\"lede\" data-reactid=\"344\">Hacks and other <\/span><!-- react-text: 345 -->digital intrusions now make up part of the anti-abortion landscape. The structure of the attacks may differ from their real-world counterparts, but the goals are the same, and the threats they pose to providers\u2019 capacity to do their jobs and deliver care are just as real\u2014even if they don\u2019t happen on the ground.<!-- \/react-text --><\/p>\n<p data-reactid=\"346\">Prevention, however, can be tough. Clinics and organizations often don\u2019t take steps to boost their cybersecurity until after an attack has hit, but at that point, it\u2019s too late. It took multiple successful hacking attempts for Whole Women\u2019s Health to make the necessary adjustments.<\/p>\n<p data-reactid=\"347\">\u201cAfter being targeted so incessantly over a short time frame, we knew immediately that we needed to develop and employ an internal system in which we closely monitored the site,\u201d said Gifford. \u201cSo we got an additional layer of website security and on a daily basis, we log in to the website to make sure that all security plug-ins are up to date and that nothing has been compromised.\u201d<\/p>\n<p data-reactid=\"348\">The attacks against Whole Woman\u2019s Health have since subsided, but who knows when they might strike again? There is no such thing as \u201cperfect\u201d cybersecurity, and with no known hacking-related arrests, clinics are pretty much on their own\u2014forced to funnel resources that could go to STI testing, contraceptives, subsidized care, and yes, abortion access into fighting faceless, nameless, enemies whose health and wellbeing are not on the line.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/cyberattacks-against-abortion-clinics\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/59d42f47f9bd7c75032230fb\/master\/pass\/Abortion_Cyberhacks-01-FA.jpg\"\/><\/p>\n<p><strong>Credit to Author: Rebecca Grant| Date: Thu, 05 Oct 2017 12:00:00 +0000<\/strong><\/p>\n<p>Abortion providers have long faced harassment, both online and and in person. But a recent wave of cyberattacks have caused havoc lately\u2014and proved difficult to stop.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714],"class_list":["post-9708","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/9708","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=9708"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/9708\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=9708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=9708"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=9708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}