The Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center (HC3) last week advised biotechnology companies specifically and the health care and public health sector generally to review a new report on a malware threat aggressively spreading through the biomanufacturing industry and take appropriation action to protect their information infrastructure. According to HC3, the malware is used to deliver ransomware, “possibly as a diversion for the actual purpose of the attack — intellectual property theft.” 

John Riggi, AHA senior advisor for cybersecurity and risk, said, “This sophisticated technical attack along with a novel strategy to utilize ransomware as a pre-text and diversion to steal biotechnology is a double-barrel cyber threat to health care. Not only will the ransomware attack disrupt and delay important biomedical research, but the theft of such research could have much broader implications. The use of the term Advanced Persistent Threat and the type of data being stolen would suggest to me the involvement of an adversarial nation state, which may seek strategic and economic advantage over the U.S. in the use of such research. Especially in light of the emergence of the omicron strain, we must continue to protect medical research and remember that health security equals economic security, and economic security equals national security.” 

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org. 

Headline
The FBI released an alert March 20 warning of a technique used by cyber actors working on behalf of the Iranian government to conduct malicious cyber activity…
Headline
The Cybersecurity and Infrastructure Security Agency March 18 released an alert urging U.S. organizations to harden their endpoint management systems following…
Headline
The Health Sector Coordinating Council Cyber Working Group and Health-ISAC (Information Sharing and Analysis Center) will host a joint cybersecurity event July…
Headline
Stryker, a medical technology company that provides services and products for hospitals, was disrupted globally by a cyberattack, the company announced March…
Headline
The White House issued an executive order March 6 to combat cybercrimes by threat groups. The order highlights how such groups can receive willing or…
Headline
The Administration for Strategic Preparedness and Response has released a new cybersecurity module for organizations to conduct risk assessments. The free…