thanks to a state directive, targeting hospitals “is not lucrative”, but we can “monetize” personal data, according to a cybersecurity professional

The Corbeil-Essonnes hospital (Essonne) has been targeted since Sunday August 21 by a cyberattack. The hackers demand a ransom of 10 million dollars.

Article written by

Posted

Update

Reading time : 1 min.

Target hospitals “is not lucrative, it is not a good operation for the attacker, because there is an instruction from the state not to pay the ransoms”explained this Tuesday on franceinfo Nicolas Arpagian, director of cybersecurity strategy at Trend Micro, author of Cybersecuritypublished by PUF.

For the Sud Francilien Hospital Center (CHSF) in Corbeil-Essonnes, south-east of Paris, a ransom demand of $10 million was formulated in English and demanded by the hacker(s). Beyond the deposit, the hospital “does not have the financial capacity to release this sum.”

There are several types of cyberattacks. When targeted, “we can imagine that the attacker is not unaware that it is a hospital, believes Nicolas Arpagian. If it’s just a villainous move for monetization purposes, the hospital that won’t pay the ransom is not the right target.”.

The real risk is the use of data that would be resold because the pirate may have a certain amount of patient data, personal and health data, which he can monetize on criminal marketplaces.

Nicolas Arpagian

director of cybersecurity strategy at Trend Micro, at franceinfo

Criminals have evolved in the middle of cyberattack. “Before, whoever designed the malicious tool was the one who exploited it and profited from it, explains Nicolas Arpagian. As soon as it becomes lucrative activities you have a kind of industrialization. People will design the malware, others will order and therefore they are not necessarily able to provide the decryption keys.”


source site-14