The Cybersecurity and Infrastructure Security Agency, FBI and National Security Agency yesterday issued an advisory to help organizations secure their systems against Conti ransomware attacks, which have included health care targets in the U.S. and other countries.

In addition, the Department of the Treasury’s Office of Foreign Assets Control this week issued an updated advisory highlighting the sanctions risks associated with ransomware payments in connection with malicious cyber-enabled activities and the proactive steps companies can take to mitigate such risks, including actions that OFAC would consider to be “mitigating factors” in any related enforcement action.

“The Russian speaking Conti ransomware gang has been implicated in some of the most disruptive ransomware attacks targeting hospitals and health systems this year,” said John Riggi, AHA senior advisor for cybersecurity and risk. “It’s continued use of the ‘double extortion’ method of ransom to demand payment for de-encryption of health data along with payment to not publicly release stolen health data jeopardizes patient privacy and patient safety. On the OFAC front, it is encouraging to see the government pursue and disrupt the illicit proceeds of these ransomware gangs. The OFAC advisory also reminds us that it is a ‘strict liability’ issue to pay ransom or facilitate payment through an OFAC designated entity. This civil and regulatory liability can only be mitigated through timely notification and cooperation with law enforcement by ransomware victims. This is another reason why guidance to not notify or cooperate with law enforcement is bad advice.”   

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org

Related News Articles

Headline
The Cybersecurity and Infrastructure Security Agency Dec. 11 released an update to its voluntary Cybersecurity Performance Goals, which includes measurable…
Headline
U.S. and international agencies are warning of potential cyberattacks on health care and other critical infrastructure from state-sponsored cyber actors in…
Headline
A critical, unauthenticated remote code execution vulnerability known as React2Shell has been added to the Cybersecurity and Infrastructure Security Agency’s…
Headline
The FBI has public resources available to help prevent exploitation by cybercriminals, who use artificial intelligence for deception. An infographic by the FBI…
Headline
A critical vulnerability has been identified in 7-Zip, a free software program used for archiving data, according to the National Institute of Standards and…
Headline
U.S. and international agencies Nov. 19 released a guide on mitigating potential cybercrimes from bulletproof hosting providers. A BPH provider is an internet…